Vulnerability Details CVE-2017-7667
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-7667
-
-
cpe:2.3:a:apache:nifi:0.0.1
-
cpe:2.3:a:apache:nifi:0.0.2
-
cpe:2.3:a:apache:nifi:0.1.0
-
cpe:2.3:a:apache:nifi:0.2.0
-
cpe:2.3:a:apache:nifi:0.2.1
-
cpe:2.3:a:apache:nifi:0.3.0
-
cpe:2.3:a:apache:nifi:0.4.0
-
cpe:2.3:a:apache:nifi:0.4.1
-
cpe:2.3:a:apache:nifi:0.5.0
-
cpe:2.3:a:apache:nifi:0.5.1
-
cpe:2.3:a:apache:nifi:0.6.0
-
cpe:2.3:a:apache:nifi:0.6.1
-
cpe:2.3:a:apache:nifi:0.7.0
-
cpe:2.3:a:apache:nifi:0.7.1
-
cpe:2.3:a:apache:nifi:0.7.2
-
cpe:2.3:a:apache:nifi:0.7.3
-
cpe:2.3:a:apache:nifi:1.0.0
-
cpe:2.3:a:apache:nifi:1.0.1
-
cpe:2.3:a:apache:nifi:1.1.0
-
cpe:2.3:a:apache:nifi:1.1.1
-
cpe:2.3:a:apache:nifi:1.1.2
-
cpe:2.3:a:apache:nifi:1.2.0