GHSA-7mqj-xgf8-p59v · Severity: medium · Ecosystem: maven — Apache NiFi Cross-site Scripting vulnerability
Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.28.0 or 2.0.0-M4 is the recommended mitigation.
Conclusion & alert: CVE-2024-45477 is rated Moderate Risk (46.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.30%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-20 | 0.96% | 1.30% | +0.34% |
| 2 | 2026-02-07 | 1.26% | 0.96% | -0.29% |
| 3 | 2025-12-13 | — | 1.26% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.6 | 3.1 | MEDIUM |
|
2.1 | 2.5 | [email protected] |
| 4.6 | 3.1 | MEDIUM |
|
2.1 | 2.5 | [email protected] |
GHSA-7mqj-xgf8-p59v · Severity: medium · Ecosystem: maven — Apache NiFi Cross-site Scripting vulnerability
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | nifi | >= 1.10.0, <= 1.27.0 | cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* |
| apache | nifi | 2.0.0 | cpe:2.3:a:apache:nifi:2.0.0:milestone1:*:*:*:*:*:* |
| apache | nifi | 2.0.0 | cpe:2.3:a:apache:nifi:2.0.0:milestone2:*:*:*:*:*:* |
| apache | nifi | 2.0.0 | cpe:2.3:a:apache:nifi:2.0.0:milestone3:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/shdv0tw9hggj7tx9pl7g93mgok2lwbj9 | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/10/28/1 |