CVE-2020-9482
Last modified
CVE-2020-9482 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests to NiFi Registry.. EPSS estimates a 2.61% chance of exploitation in the next 30 days.
Description
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests to NiFi Registry.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi Registry | >= 0.1.0, <= 0.5.0 |
References
- https://nifi.apache.org/registry-security.html#CVE-2020-9482Patch, Vendor Advisory
- https://nifi.apache.org/registry-security.html#CVE-2020-9482Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9482?
How severe is CVE-2020-9482?
How do I fix CVE-2020-9482?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-9476ARRIS TG1692A devices allow remote attackers to discover the…7.5
- CVE-2020-9477An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 dev…9.8
- CVE-2020-9478An issue was discovered in Rubrik 5.0.3-2296. An OS command …8.8
- CVE-2020-9479When loading a UDF, a specially crafted zip file could allow…5.5
- CVE-2020-9480In Apache Spark 2.4.5 and earlier, a standalone resource man…9.8
- CVE-2020-9481Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.…7.5
- CVE-2020-9483**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking sto…7.5
- CVE-2020-9484When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.…7
- CVE-2020-9485An issue was found in Apache Airflow versions 1.10.10 and be…6.1
- CVE-2020-9486In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless executio…7.5
- CVE-2020-9487In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one…7.5
- CVE-2020-9488Improper validation of certificate with host mismatch in Apa…3.7
Are you affected by CVE-2020-9482?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
