HIGH
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content
Published Oct 1, 2020
7.5
HIGHCVSS 3.1
EPSS 3.05%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.