
Cloud Vulnerability DB
A community-led vulnerabilities database
In Apache NiFi versions 1.0.0 to 1.11.4, a vulnerability was discovered related to the download token mechanism. The issue was identified and assigned CVE-2020-9487, with the initial disclosure date of October 1, 2020. The vulnerability affected the one-time password system used for downloads in Apache NiFi (NVD Database).
The vulnerability stems from a design flaw in the NiFi download token (one-time password) mechanism which utilized a fixed cache size. The critical aspect of this vulnerability is that the system did not authenticate requests to create download tokens, only validating them when attempting to use the token to access content. The severity of this vulnerability is rated as HIGH with a CVSS 3.1 Base Score of 7.5 (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The vulnerability is classified under CWE-306 (Missing Authentication for Critical Function) (NVD Database).
The primary impact of this vulnerability is the potential for denial of service attacks. When exploited, legitimate users could be prevented from requesting download tokens, effectively blocking their access to necessary content. The vulnerability affects the availability of the system while not compromising confidentiality or integrity (NVD Database).
The vulnerability is particularly concerning as it can be exploited by unauthenticated users who could repeatedly request download tokens. The attack vector is network-accessible (AV:N) with low attack complexity (AC:L), requiring no privileges (PR:N) or user interaction (UI:N) (NVD Database).
The vulnerability was addressed in subsequent versions of Apache NiFi after version 1.11.4. Users running affected versions (1.0.0 to 1.11.4) should upgrade to a patched version to mitigate this security risk (NVD Database).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."