oss-sec mailing list archives

CVE-2025-27017: Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record


From: Pierre Villard <pvillard () apache org>
Date: Tue, 11 Mar 2025 16:12:00 +0100

Affected versions:

- Apache NiFi 1.13.0 through 2.2.0
- Apache NiFi 2.3.0 unaffected

Description:

Apache NiFi 1.13.0 through 2.2.0 includes the username and password
used to authenticate with MongoDB in the NiFi provenance events that
MongoDB components generate during processing. An authorized user with
read access to the provenance events of those processors may see the
credentials information. Upgrading to Apache NiFi 2.3.0 is the
recommended mitigation, which removes the credentials from provenance
event records.

This issue is being tracked as NIFI-14272

Credit:

Robert Creese (finder)

References:

https://nifi.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-27017
https://issues.apache.org/jira/browse/NIFI-14272


Current thread: