CVE-2020-9487
Java vulnerability analysis and mitigation

Overview

In Apache NiFi versions 1.0.0 to 1.11.4, a vulnerability was discovered related to the download token mechanism. The issue was identified and assigned CVE-2020-9487, with the initial disclosure date of October 1, 2020. The vulnerability affected the one-time password system used for downloads in Apache NiFi (NVD Database).

Technical details

The vulnerability stems from a design flaw in the NiFi download token (one-time password) mechanism which utilized a fixed cache size. The critical aspect of this vulnerability is that the system did not authenticate requests to create download tokens, only validating them when attempting to use the token to access content. The severity of this vulnerability is rated as HIGH with a CVSS 3.1 Base Score of 7.5 (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The vulnerability is classified under CWE-306 (Missing Authentication for Critical Function) (NVD Database).

Impact

The primary impact of this vulnerability is the potential for denial of service attacks. When exploited, legitimate users could be prevented from requesting download tokens, effectively blocking their access to necessary content. The vulnerability affects the availability of the system while not compromising confidentiality or integrity (NVD Database).

Exploitability

The vulnerability is particularly concerning as it can be exploited by unauthenticated users who could repeatedly request download tokens. The attack vector is network-accessible (AV:N) with low attack complexity (AC:L), requiring no privileges (PR:N) or user interaction (UI:N) (NVD Database).

Mitigation and workarounds

The vulnerability was addressed in subsequent versions of Apache NiFi after version 1.11.4. Users running affected versions (1.0.0 to 1.11.4) should upgrade to a patched version to mitigate this security risk (NVD Database).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73644CRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesAug 13, 2026
CVE-2026-73507HIGH7.5
  • Java logoJava
  • io.netty:netty-codec-xml
NoYesAug 13, 2026
CVE-2026-49989HIGH7.1
  • Java logoJava
  • io.crate:crate
NoYesAug 14, 2026
CVE-2026-53660HIGH7
  • Java logoJava
  • org.openidentityplatform.openam:openam-core
NoYesAug 14, 2026
CVE-2026-73508MEDIUM5.3
  • Java logoJava
  • keycloak-fips-26.7
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management