CVE-2024-56512 is a medium-severity vulnerability affecting Apache NiFi versions 1.10.0 through 2.0.0. It involves missing fine-grained authorization checks when authenticated users create new Process Groups, allowing them to access unauthorized Parameter Contexts, Controller Services, or Parameter Providers. This could lead to information disclosure of non-sensitive parameter values or the use of components they are not authorized for. While there is no evidence of active exploitation, a Nuclei template exists for information disclosure, and the vulnerability has a high FAUCET Risk Score of 96/100, indicating potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.10.0, < 2.1.0CPE matchmatch criteria | cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* | ||
>= 1.10.0, <= 2.0.0CPE match | cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:L/U:Green
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.