Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-8748

In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.4%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2016-8748
  • Apache » Nifi » Version: N/A
    cpe:2.3:a:apache:nifi:-
  • Apache » Nifi » Version: 0.0.1
    cpe:2.3:a:apache:nifi:0.0.1
  • Apache » Nifi » Version: 0.0.2
    cpe:2.3:a:apache:nifi:0.0.2
  • Apache » Nifi » Version: 0.1.0
    cpe:2.3:a:apache:nifi:0.1.0
  • Apache » Nifi » Version: 0.2.0
    cpe:2.3:a:apache:nifi:0.2.0
  • Apache » Nifi » Version: 0.2.1
    cpe:2.3:a:apache:nifi:0.2.1
  • Apache » Nifi » Version: 0.3.0
    cpe:2.3:a:apache:nifi:0.3.0
  • Apache » Nifi » Version: 0.4.0
    cpe:2.3:a:apache:nifi:0.4.0
  • Apache » Nifi » Version: 0.4.1
    cpe:2.3:a:apache:nifi:0.4.1
  • Apache » Nifi » Version: 0.5.0
    cpe:2.3:a:apache:nifi:0.5.0
  • Apache » Nifi » Version: 0.5.1
    cpe:2.3:a:apache:nifi:0.5.1
  • Apache » Nifi » Version: 0.6.0
    cpe:2.3:a:apache:nifi:0.6.0
  • Apache » Nifi » Version: 0.6.1
    cpe:2.3:a:apache:nifi:0.6.1
  • Apache » Nifi » Version: 0.7.0
    cpe:2.3:a:apache:nifi:0.7.0
  • Apache » Nifi » Version: 0.7.1
    cpe:2.3:a:apache:nifi:0.7.1
  • Apache » Nifi » Version: 0.7.2
    cpe:2.3:a:apache:nifi:0.7.2
  • Apache » Nifi » Version: 0.7.3
    cpe:2.3:a:apache:nifi:0.7.3
  • Apache » Nifi » Version: 0.7.4
    cpe:2.3:a:apache:nifi:0.7.4
  • Apache » Nifi » Version: 1.0.0
    cpe:2.3:a:apache:nifi:1.0.0
  • Apache » Nifi » Version: 1.1.0
    cpe:2.3:a:apache:nifi:1.1.0


Contact Us

Shodan ® - All rights reserved