CVE-2022-26850
Insufficiently protected credentials
6.5
MEDIUM
CVSS 3.1
EPSS 1.4%
描述
When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. On most platforms, the operating system temporary directory has global read permissions. NiFi immediately moved the temporary file to the final configuration directory, which significantly limited the window of opportunity for access. NiFi 1.16.0 includes updates to replace the Login Identity Providers configuration without writing a file to the operating system temporary directory.
如何修補 CVE-2022-26850
要修補 CVE-2022-26850,請將受影響套件升級到下列已修補版本。
- —升級至 1.16.0 或更新版本
- —升級至 1.16 或更新版本
CVE-2022-26850 正在被利用嗎?
低 — EPSS 為 1.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 1.14.0, < 1.16.0
- from 0, < 1.16
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |