HIGH8.8CVE-2026-39816Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService >= 2.0.0, < 2.9.0
HIGH8.8CVE-2023-36542Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources >= 0.0.2, <= 1.22.0
HIGH8.8CVE-2023-34468Apache NiFi: Potential Code Injection with Database Services using H2 >= 0.0.2, < 1.22.0
HIGH8.8Improper Neutralization of Command Elements in Shell User Group Provider
>= 1.10.0, <= 1.16.2
HIGH8.1Deserialization of untrusted data in jackson-databind
>= 1.7.0, <= 1.12.1
HIGH7.9Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt
>= 0.7.0, < 1.24.0
HIGH7.5Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes
>= 1.2.0, <= 1.19.1
HIGH7.5Improper Restriction of XML External Entity References in Multiple Components
>= 0.0.1, <= 1.16.0
HIGH7.5Inadequate Encryption Strength in Apache NiFi
>= 1.0.0, <= 1.11.4
HIGH7.5Missing Authentication for Critical Function in Apache NiFi
>= 1.0.0, <= 1.11.4
HIGH7.5Insertion of Sensitive Information into Log File in Apache NiFi Stateless
>= 1.0.0, <= 1.11.4
HIGH7.5Insertion of Sensitive Information into Log File in Apache NiFi
>= 0.0.1, <= 1.11.0
MEDIUM6.5Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs
>= 1.21.0, < 1.23.1
MEDIUM6.5Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components
>= 1.8.0, <= 1.21.0
MEDIUM6.5Insufficiently protected credentials
>= 1.14.0, < 1.16.0
MEDIUM6.5Apache NiFi information disclosure by XXE
>= 0.1.0, < 1.15.1
MEDIUM6.1Cross-site scripting in Apache NiFi
>= 1.0.0, <= 1.10.0
MEDIUM5.5Improper Restriction of XML External Entity Reference in Apache NiFi
>= 1.0.0, <= 1.11.4
MEDIUM5.4Apache NiFi: Missing Complete Authorization for Parameter and Service References
>= 1.10.0, < 2.1.0
MEDIUM5.3Apache NiFi Insertion of Sensitive Information into Log File
>= 1.10.0, <= 1.10.0
MEDIUM4.6Apache NiFi: Improper Neutralization of Input in Parameter Description
>= 1.10.0, < 1.28.0
—Apache NiFi: Missing Validation for Proxy Host Headers
>= 0.0.1, < 2.10.0
—Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents
>= 1.12.0, < 2.10.0
—Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
>= 1.2.0, < 2.10.0
—Apache NiFi: Incorrect Authorization for Configuration Verification Requests
>= 1.15.0, < 2.10.0
—Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates
>= 1.1.0, < 2.8.0
—Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor
>= 1.20.0, < 2.7.0