When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apache
Published: 2019-11-19T21:34:11
Updated: 2020-01-24T04:06:01
Reserved: 2019-03-26T00:00:00
Link: CVE-2019-10083
JSON object: View
NVD Information
Status : Modified
Published: 2019-11-19T22:15:11.207
Modified: 2023-11-07T03:02:22.487
Link: CVE-2019-10083
JSON object: View
Redhat Information
No data.
CWE