CVE-2020-1928

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
28/01/2020
Last modified:
07/11/2023

Description

An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:nifi:1.10.0:*:*:*:*:*:*:*