{"id":"GHSA-w4fj-ccr6-7pcp","summary":"Apache NiFi Insertion of Sensitive Information into Log File","details":"An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.","aliases":["BIT-nifi-2020-1928","CVE-2020-1928"],"modified":"2025-09-15T07:42:09.959845Z","published":"2022-01-06T20:40:56Z","database_specific":{"nvd_published_at":"2020-01-28T01:15:00Z","cwe_ids":["CWE-200","CWE-532"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-03-29T14:27:46Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-1928"},{"type":"WEB","url":"https://github.com/apache/nifi/pull/3935"},{"type":"WEB","url":"https://github.com/apache/nifi/commit/42cb6e84898e66672878f61f99543d6af3c0a567"},{"type":"PACKAGE","url":"https://github.com/apache/nifi"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e@%3Cusers.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1@%3Cusers.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b@%3Cusers.tomcat.apache.org%3E"},{"type":"WEB","url":"https://nifi.apache.org/security.html#CVE-2020-1928"}],"affected":[{"package":{"name":"org.apache.nifi:nifi-parameter","ecosystem":"Maven","purl":"pkg:maven/org.apache.nifi/nifi-parameter"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.10.0"},{"fixed":"1.11.0"}]}],"versions":["1.10.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-w4fj-ccr6-7pcp/GHSA-w4fj-ccr6-7pcp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}