CVE-2017-7667

Description

Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.392

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-7667,CVE-2017-7665 are fixed in Apache-nifi-api 0.7.4Windows
Vulnerabilities CVE-2017-7667,CVE-2017-7665 are fixed in Apache-nifi-api 1.3.0Windows
Vulnerabilities CVE-2017-7667,CVE-2017-7665 are fixed in Apache-Nifi-api for Linux 0.7.4Linux
Vulnerabilities CVE-2017-7667,CVE-2017-7665 are fixed in Apache-Nifi-api for Linux 1.3.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234