Rewterz

Rewterz Threat Advisory – VMware Horizon Client for Linux Vulnerabilities

April 7, 2022
Rewterz

Rewterz Threat Update – Anonymous Collective’s Activity Round-Up – Russian-Ukrainian Cyber Warfare

April 7, 2022

Rewterz Threat Advisory – CVE-2022-26850 – Apache NiFi Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-26850

Apache NiFi could allow a remote authenticated attacker to obtain sensitive information, caused by the storage of username and a bcrypt hash of the configured password in the Login Identity Providers configuration file when creating or updating credentials for single-user access. By gaining access to the configuration file, an attacker could exploit this vulnerability to obtain username and password information, and use this information to launch further attacks against the affected system.

Impact

Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2022-26850

Affected Vendors

Apache

Affected Products

Apache NiFi 1.15.0

Remediation

Upgrade to the latest version of Apache NiFi, available from the Apache Web site.

Apache Web site

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.