{"id":"GHSA-q594-2475-8v9f","summary":"Unencrypted passwords","details":"A vulnerability found in Apache NIFI before v0.4.0-RC2. Passwords of InvokeHTTP weren?t encrypted.","modified":"2024-12-01T05:35:46.731834Z","published":"2021-02-24T19:33:17Z","withdrawn":"2021-02-24T19:33:17Z","database_specific":{"github_reviewed_at":"2019-10-25T17:13:12Z","nvd_published_at":null,"cwe_ids":[],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/apache/nifi/commit/b4bfcc1f21fed3209bf4a8f187616cdbb3d1a5c9"}],"affected":[{"package":{"name":"org.apache.nifi:nifi-standard-processors","ecosystem":"Maven","purl":"pkg:maven/org.apache.nifi/nifi-standard-processors"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.0"}]}],"versions":["0.0.1-incubating","0.0.2-incubating","0.1.0-incubating","0.2.0-incubating","0.2.1","0.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-q594-2475-8v9f/GHSA-q594-2475-8v9f.json"}}],"schema_version":"1.9.0"}