CVE-2018-17193
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 2.8%
probabilidade de exploração
2.8%top 14% das CVEs
exploração observada
nãonenhuma fonte reporta
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Produtos afetados
Apache Software Foundation · Apache NiFi