CVE-2020-9491
Inadequate Encryption Strength in Apache NiFi
7.5
HIGH
CVSS 3.1
EPSS 1.3%
Description
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS v1.0 or v1.1.
How to fix CVE-2020-9491
To remediate CVE-2020-9491, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 1.12.0-RC1 or later
Is CVE-2020-9491 being exploited?
Low — EPSS is 1.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 1.0.0, <= 1.11.4
- >= 1.2.0, < 1.12.0-RC1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |