CVE-2025-27017
Last modified
CVE-2025-27017 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those processors may see the credentials information. EPSS estimates a 1.14% chance of exploitation in the next 30 days.
Description
Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those processors may see the credentials information. Upgrading to Apache NiFi 2.3.0 is the recommended mitigation, which removes the credentials from provenance event records.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:L/U:Green
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | >= 1.13.0, < 2.3.0 |
References
- https://lists.apache.org/thread/d4n5474jkhp82dvnht13pjtlfx7bhn5qMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/03/11/1Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-27017?
How severe is CVE-2025-27017?
How do I fix CVE-2025-27017?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27011Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2025-27012Cross-Site Request Forgery (CSRF) vulnerability in a1post A1…8.8
- CVE-2025-27013Missing Authorization vulnerability in QuanticaLabs MediCent…5.3
- CVE-2025-27014Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-27015Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2025-27016Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-27018Improper Neutralization of Special Elements used in an SQL C…6.3
- CVE-2025-27019Remote shell service (RSH) in Infinera MTC-9 version R22.1.1…9.8
- CVE-2025-2702A vulnerability, which was classified as critical, has been …6.3
- CVE-2025-27020Improper configuration of the SSH service in Infinera MTC-9 …9.8
- CVE-2025-27021The misconfiguration in the sudoers configuration of the ope…7.8
- CVE-2025-27022A path traversal vulnerability of the WebGUI HTTP endpoint i…6.5
Are you affected by CVE-2025-27017?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
