Vulnerability Details CVE-2020-1933
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.5%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-1933
-
cpe:2.3:a:apache:nifi:1.0.0
-
cpe:2.3:a:apache:nifi:1.0.1
-
cpe:2.3:a:apache:nifi:1.1.0
-
cpe:2.3:a:apache:nifi:1.1.1
-
cpe:2.3:a:apache:nifi:1.1.2
-
cpe:2.3:a:apache:nifi:1.10.0
-
cpe:2.3:a:apache:nifi:1.2.0
-
cpe:2.3:a:apache:nifi:1.3.0
-
cpe:2.3:a:apache:nifi:1.4.0
-
cpe:2.3:a:apache:nifi:1.5.0
-
cpe:2.3:a:apache:nifi:1.6.0
-
cpe:2.3:a:apache:nifi:1.7.0
-
cpe:2.3:a:apache:nifi:1.7.1
-
cpe:2.3:a:apache:nifi:1.8.0
-
cpe:2.3:a:apache:nifi:1.9.0
-
cpe:2.3:a:apache:nifi:1.9.1
-
cpe:2.3:a:apache:nifi:1.9.2
-
cpe:2.3:a:mozilla:firefox:-