Skip to main content
EPSS 3.1%top 13%

Apache NiFi: Missing Complete Authorization for Parameter and Service References (CVE-2024-56512)

0
Low
Published: 09/12/2025 (09/12/2025, 11:47:06 UTC)
Source: GCVE Database
Product: nifi

Description

Apache NiFi versions 1.10.0 through 2.0.0 have a vulnerability where fine-grained authorization checks are missing for Parameter Contexts, Controller Services, and Parameter Providers when creating new Process Groups. Authenticated users with permission to create Process Groups could bypass authorization checks on these components, potentially accessing or using components they are not authorized for. This issue is limited to deployments using component-based authorization policies. Upgrading to Apache NiFi 2.1.0 addresses this vulnerability by enforcing proper authorization checks.

Affected software

Bitnamimore threats →ghsa
nifi
pkg:bitnami/nifi
Affected versions
>=1.10.0 <2.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 13:38:07 UTC

Technical Analysis

Apache NiFi versions 1.10.0 through 2.0.0 lack complete authorization verification when creating new Process Groups that bind to Parameter Contexts or reference Controller Services and Parameter Providers. Specifically, if a Process Group does not reference any Parameter values, the framework fails to check user authorization for the bound Parameter Context, allowing clients to download non-sensitive Parameter values. Additionally, authorization checks are missing for referenced Controller Services and Parameter Providers, enabling unauthorized use of these components. This vulnerability affects only authenticated users authorized to create Process Groups and deployments with component-based authorization policies. The issue is fixed in Apache NiFi 2.1.0, which includes proper authorization checks for these references during Process Group creation.

Potential Impact

Authenticated users with permission to create Process Groups can bypass fine-grained authorization controls on Parameter Contexts, Controller Services, and Parameter Providers. This allows them to download non-sensitive Parameter values and use Controller Services or Parameter Providers they are otherwise unauthorized to access. The impact is limited in scope to users with Process Group creation rights and deployments using component-based authorization policies. No known exploits are reported in the wild.

Mitigation Recommendations

Upgrade Apache NiFi to version 2.1.0 or later, which includes fixes to enforce authorization checks for Parameter Contexts, Controller Services, and Parameter Providers during Process Group creation. This is the recommended and official remediation. No additional mitigations are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BIT-nifi-2024-56512
Osv Schema Version
1.6.2
Aliases
["CVE-2024-56512"]
Ecosystems
["Bitnami"]
Database Specific Severity
Low

Threat ID: 6aa005fdacd9273b49ab6915

Added to database: 09/08/2026, 12:56:29 UTC

Last enriched: 09/08/2026, 13:38:07 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 34

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses