Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2025/VULN142

_____________________________________________________________________

DATE                : 14/03/2025

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache NiFi versions prior to
                                        2.3.0.

=====================================================================
https://lists.apache.org/thread/hkq7wbb01ldgt3lr4o3d1zrthqdzol5t
_____________________________________________________________________

CVE-2025-27017: Apache NiFi: Potential Insertion of MongoDB Password
in Provenance Record


Affected versions:

- Apache NiFi 1.13.0 through 2.2.0
- Apache NiFi 2.3.0 unaffected

Description:

Apache NiFi 1.13.0 through 2.2.0 includes the username and password
used to authenticate with MongoDB in the NiFi provenance events that
MongoDB components generate during processing. An authorized user with
read access to the provenance events of those processors may see the
credentials information. Upgrading to Apache NiFi 2.3.0 is the
recommended mitigation, which removes the credentials from provenance
event records.

This issue is being tracked as NIFI-14272

Credit:

Robert Creese (finder)

References:

https://nifi.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-27017
https://issues.apache.org/jira/browse/NIFI-14272


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
