Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-10674

Variable access through evaluateELString()

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    Description

      Not sure it's bug, but security breach. With expression language i can view content of sensitive parameter from parameter context. For example:

      1. Create parameter context with sensitive parameter
      2. Create variable with name of this sensitive parameter #{sample}
      3. Create simple flow with EL expression: ${secret:evaluateELString()}
      4. Content of this flowfile will contain sensitive value from parameter

      I suppose evaluateELString shouldn't access to sensitive parameters.

      Attachments

        Issue Links

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            exceptionfactory David Handermann
            gogolev.sergey Gogolev Sergey
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 1h 10m
                1h 10m

                Slack

                  Issue deployment