Apache NiFi has identified four security vulnerabilities impacting its web API, including authorization-bypass flaws, remote code execution potential, and resource exhaustion related to gzip-compressed REST requests This article explores apache nifi 11. . Organizations utilizing affected versions of Apache NiFi should upgrade to version 2.11.0, which resolves all reported issues. An attacker could create a compressed request that expands during decompression, causing NiFi to allocate excessive memory and potentially leading to resource exhaustion and service disruptions when exposed to untrusted or inadequately restricted clients.

Apache NiFi 2.11.0 mitigates this issue by moving response compression to Jetty Server and disabling gzip decompression on HTTP requests. These proposed values could override existing configurations during validation, enabling an authorized user to invoke predefined component validation methods using attacker-controlled settings.

NiFi allows deleting Parameter Contexts using a supplied identifier but does not verify if it matches the Asset's stored owner, potentially enabling unauthorized Asset deletions with different authorization levels. Administrators must focus on updating to Apache NiFi version 2.11.0, reviewing component-level and Parameter Context authorization policies, and limiting REST API access to authorized networks and authenticated users. By cutting through SOC investigation blind spots and containing threats earlier, ANY.RUN can help minimize response costs and business disruptions.