apache nifi CVE-2018-17193 is a vulnerability in Apache NiFi
Published on December 19, 2018

The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

NVD


Products Associated with CVE-2018-17193

Want to know whenever a new CVE is published for Apache NiFi? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache NiFi Version Apache NiFi 1.0.0 - 1.7.1 is affected by CVE-2018-17193

Exploit Probability

EPSS
1.59%
Percentile
81.37%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.