You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@nifi.apache.org by "Andy LoPresto (Jira)" <ji...@apache.org> on 2020/03/26 00:26:00 UTC

[jira] [Updated] (NIFI-7153) Limit length of component property values

     [ https://issues.apache.org/jira/browse/NIFI-7153?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Andy LoPresto updated NIFI-7153:
--------------------------------
    Fix Version/s: 1.12.0
           Status: Patch Available  (was: Open)

> Limit length of component property values
> -----------------------------------------
>
>                 Key: NIFI-7153
>                 URL: https://issues.apache.org/jira/browse/NIFI-7153
>             Project: Apache NiFi
>          Issue Type: Improvement
>          Components: Core Framework, Core UI
>    Affects Versions: 1.11.1
>            Reporter: Andy LoPresto
>            Assignee: Troy Melhase
>            Priority: Major
>              Labels: security
>             Fix For: 1.12.0
>
>          Time Spent: 11h 40m
>  Remaining Estimate: 0h
>
> Component properties can vary wildly in their use - some are integers or booleans, while others are simple names, and some can accept arbitrary schema definitions, code and config blocks, etc. There is no universal length limit that can be applied, so the general classes of property should have reasonable limits to avoid denial of service attacks through malicious setting of arbitrary property values. 



--
This message was sent by Atlassian Jira
(v8.3.4#803005)