Improper Neutralization of Input in Advanced User Interface for Jolt
High severity
GitHub Reviewed
Published
Nov 28, 2023
to the GitHub Advisory Database
•
Updated Nov 28, 2023
Package
Affected versions
< 1.24.0
Patched versions
1.24.0
Description
Published by the National Vulnerability Database
Nov 27, 2023
Published to the GitHub Advisory Database
Nov 28, 2023
Reviewed
Nov 28, 2023
Last updated
Nov 28, 2023
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.
References