You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@nifi.apache.org by "ASF subversion and git services (Jira)" <ji...@apache.org> on 2022/04/25 14:38:00 UTC

[jira] [Commented] (NIFI-9954) Upgrade to Spring Framework 5.3.19 and Spring Boot 2.6.7

    [ https://issues.apache.org/jira/browse/NIFI-9954?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17527535#comment-17527535 ] 

ASF subversion and git services commented on NIFI-9954:
-------------------------------------------------------

Commit 6ae1590aef4a2104595458b7fba31601eac12b29 in nifi's branch refs/heads/main from David Handermann
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=6ae1590aef ]

NIFI-9954 This closes #5993. Upgraded Spring Framework from 5.3.18 to 5.3.19

- Upgraded Spring Security from 5.6.2 to 5.6.3
- Upgraded Log4j 2 from 2.17.1 to 2.17.2
- Upgraded Spring Boot from 2.6.6 to 2.6.7 for NiFi Registry

Signed-off-by: Joe Witt <jo...@apache.org>


> Upgrade to Spring Framework 5.3.19 and Spring Boot 2.6.7
> --------------------------------------------------------
>
>                 Key: NIFI-9954
>                 URL: https://issues.apache.org/jira/browse/NIFI-9954
>             Project: Apache NiFi
>          Issue Type: Improvement
>          Components: Core Framework, NiFi Registry
>            Reporter: David Handermann
>            Assignee: David Handermann
>            Priority: Major
>              Labels: dependency-upgrade
>             Fix For: 1.17.0, 1.16.1
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> Spring Framework 5.3.19 includes several bug fixes, including a resolution for [CVE-2022-22968|https://tanzu.vmware.com/security/cve-2022-22968], which impacts data binding classes that are not used in regular NiFi framework operations.
> Spring Boot 2.6.7 incorporates Spring Framework 5.3.19 and several other transitive dependency upgrades for NiFi Registry.
> Spring Security 5.6.3 also includes a small number of improvements over the current version of 5.6.2.



--
This message was sent by Atlassian Jira
(v8.20.7#820007)