GHSA-v4p2-2w39-mhrj · Severity: high · Ecosystem: maven — Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization
Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserialization without filtering. Unfiltered Java object deserialization does not provide protection against crafted state information stored in the cache server configured for GetAsanaObject. Exploitation requires an Apache NiFi system running with the GetAsanaObject Processor, and direct access to the configured cache server. Upgrading to Apache NiFi 2.7.0 is the recommended mitigation, which replaces Java Object serialization with JSON serialization. Removing the GetAsanaObject Processor located in the nifi-asana-processors-nar bundle also prevents exploitation.
Conclusion & alert: CVE-2025-66524 is rated Moderate Risk (40.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.12%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-16 | 0.15% | 0.12% | -0.03% |
| 2 | 2026-02-25 | 0.06% | 0.15% | +0.10% |
| 3 | 2025-12-25 | — | 0.06% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 4.0 | HIGH |
|
— | — | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
GHSA-v4p2-2w39-mhrj · Severity: high · Ecosystem: maven — Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/k9h004ydjg7opdvxr0nfywtzf33z60d7 | Mailing List Issue Tracking Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/12/18/2 | Mailing List |