CVE Explorer
CVE-2025-66524
Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserialization without filtering. Unfiltered Java object deserialization does not provide protection against crafted state information stored in the cache server configured for GetAsanaObject. Exploitation requires an Apache Ni
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageName":"org.apache.nifi:nifi-asana-processors","product":"Apache NiFi","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"2.6.0","status":"affected","version":"1.20.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b19e11208a967ce33d6a27e51ef5afc747c93c47ba86fc078383e9eaa672c3e8 · sha256:9019061ae86cbad1… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"YES","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.5,"baseSeverity":"HIGH","privilegesRequired":"HIGH","providerUrgency":"GREEN","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Green","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityIm…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b19e11208a967ce33d6a27e51ef5afc747c93c47ba86fc078383e9eaa672c3e8 · sha256:9019061ae86cbad1… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b19e11208a967ce33d6a27e51ef5afc747c93c47ba86fc078383e9eaa672c3e8 · sha256:9019061ae86cbad1… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"http://www.openwall.com/lists/oss-security/2025/12/18/2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b19e11208a967ce33d6a27e51ef5afc747c93c47ba86fc078383e9eaa672c3e8 · sha256:9019061ae86cbad1… · /containers/adp/0/references/0
{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/k9h004ydjg7opdvxr0nfywtzf33z60d7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b19e11208a967ce33d6a27e51ef5afc747c93c47ba86fc078383e9eaa672c3e8 · sha256:9019061ae86cbad1… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.