Reflected cross-site scripting (XSS) In org.apache.nifi:nifi
Description
Cross-site Scripting in Apache NiFi In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 1.0.1, 1.1.1 |
Aliases
1. 2. 3. 4.
References
1. 2.