CVE-2017-7667: Apache Nifi
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
Affected products
- Apache Nifi: up to and including 0.7.3; version 1.0.0 only; version 1.0.1 only; version 1.1.0 only; version 1.1.1 only; version 1.1.2 only; …
Published 2017-06-12. Last modified 2026-06-17.