Security Advisory
CVE-2017-7667
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.