apache nifi CVE-2020-9486 is a vulnerability in Apache NiFi
Published on October 1, 2020

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

NVD


Products Associated with CVE-2020-9486

Want to know whenever a new CVE is published for Apache NiFi? stack.watch will email you.

 

Exploit Probability

EPSS
1.26%
Percentile
79.18%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.