CVE-2020-1928: Apache Nifi
Medium severity, CVSS 5.3. EPSS: 4% chance of exploitation in the next 30 days.
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.
Affected products
- Apache Nifi: version 1.10.0 only
Published 2020-01-28. Last modified 2026-06-17.