You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@nifi.apache.org by "Mike R (Jira)" <ji...@apache.org> on 2022/11/11 17:21:00 UTC

[jira] [Created] (NIFI-10804) Update okhttp-digest to version 2.7

Mike R created NIFI-10804:
-----------------------------

             Summary: Update okhttp-digest to version 2.7
                 Key: NIFI-10804
                 URL: https://issues.apache.org/jira/browse/NIFI-10804
             Project: Apache NiFi
          Issue Type: Improvement
    Affects Versions: 1.18.0
            Reporter: Mike R


The version of okhttp-digest used in the NiFi lookup services is outdated and should be updated to remediate [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]

The current version used there is 2.5, with the most recent version being 2.7. Release notes https://github.com/rburgst/okhttp-digest/blob/2.7/release-notes.md



--
This message was sent by Atlassian Jira
(v8.20.10#820010)