Author: pwnhxl
Classification
CWE-ID: CWE-285
CVSS-Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CVSS-Score: 8.6
Apache NiFi server was able to be accessed because no authentication was required.
Reference
- https://github.com/jm0x0/apache_nifi_processor_rce
Metadata
max-request: 1
verified: true
shodan-query: title:"NiFi"
fofa-query: title="nifi" && body="Did you mean"