You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@nifi.apache.org by "David Handermann (Jira)" <ji...@apache.org> on 2023/03/28 18:31:00 UTC

[jira] [Created] (NIFI-11356) Upgrade Nimbus JOSE JWT to 9.31

David Handermann created NIFI-11356:
---------------------------------------

             Summary: Upgrade Nimbus JOSE JWT to 9.31
                 Key: NIFI-11356
                 URL: https://issues.apache.org/jira/browse/NIFI-11356
             Project: Apache NiFi
          Issue Type: Improvement
          Components: Core Framework, Extensions, NiFi Registry
            Reporter: David Handermann
            Assignee: David Handermann


Nimbus JOSE JWT version 9 prior to 9.24.0 include a shaded version of JSON Smart 2.4.8, which is vulnerable to resource exhaustion as described in [CVE-2023-1370|https://nvd.nist.gov/vuln/detail/CVE-2023-1370]. More recent versions of Nimbus JOSE JWT depend on Gson and are not subject to the vulnerability.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)