Description
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
Remediation
References
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
https://nifi.apache.org/security.html#CVE-2019-10083
Related Vulnerabilities
CVE-2023-31126 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml
CVE-2019-1003095 Vulnerability in maven package org.jenkins-ci.plugins:perfectomobile
CVE-2014-0050 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2023-26471 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-async-api
CVE-2022-36914 Vulnerability in maven package org.jenkins-ci.plugins:files-found-trigger