CVE-2020-9491

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
01/10/2020
Last modified:
07/11/2023

Description

In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS v1.0 or v1.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* 1.0.0 (including) 1.11.4 (including)