In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS v1.0 or v1.1.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2020-10-01T19:57:34

Updated: 2020-10-06T00:15:40

Reserved: 2020-03-01T00:00:00


Link: CVE-2020-9491

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-10-01T20:15:14.330

Modified: 2023-11-07T03:26:55.580


Link: CVE-2020-9491

JSON object: View

cve-icon Redhat Information

No data.

CWE