{"id":"CVE-2020-1942","aliases":["BIT-nifi-2020-1942","GHSA-7q8g-gpfp-v8gx"],"url":"https://o3.security/vulnerability/CVE-2020-1942","summary":"Insertion of Sensitive Information into Log File in Apache NiFi","details":"In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.","published":"2020-02-11T21:15:11.113Z","modified":"2026-07-08T19:01:53.587426Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.03124,"percentile":0.8684,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.nifi:nifi-framework-core","fixedVersion":"1.12.0-RC1"},{"ecosystem":"Maven","name":"org.apache.nifi:nifi-security-utils","fixedVersion":"1.12.0-RC1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nifi.apache.org/security.html#CVE-2020-1942"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:01:53.587426Z"}}