CVE-2016-8748

Description

In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.406

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-8748 are fixed in Apache-nifi-api 1.0.1Windows
Vulnerabilities CVE-2016-8748 are fixed in Apache-nifi-api 1.1.1Windows
Vulnerabilities CVE-2016-8748 are fixed in Apache-Nifi-api for Linux 1.0.1Linux
Vulnerabilities CVE-2016-8748 are fixed in Apache-Nifi-api for Linux 1.1.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234