CVE-2023-49145 Details
Description
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.apache.org/thread/j8rd0qsvgoj0khqck5f49jfbp0fm8r1o | CVE | Mailing ListVendor Advisory |
| https://nifi.apache.org/security.html#CVE-2023-49145 | CVE | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2023/11/27/5 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/j8rd0qsvgoj0khqck5f49jfbp0fm8r1o | [email protected] | Mailing ListVendor Advisory |
| https://nifi.apache.org/security.html#CVE-2023-49145 | [email protected] | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2023/11/27/5 | [email protected] | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache nifi | >= 0.7.0, < 1.24.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 1, 2023 | Initial Analysis | [email protected] |
| Nov 28, 2023 | CVE Modified | [email protected] |
| Nov 27, 2023 | New CVE Received | [email protected] |