An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.
| Software | From | Fixed in |
|---|---|---|
| apache / nifi | 1.10.0 | 1.10.0.x |
org.apache.nifi / nifi
|
1.10.0 | 1.10.0.x |
org.apache.nifi / nifi
|
1.10.0 | 1.11.0-RC1 |