You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@nifi.apache.org by "Mike R (Jira)" <ji...@apache.org> on 2022/11/11 17:21:00 UTC
[jira] [Created] (NIFI-10804) Update okhttp-digest to version 2.7
Mike R created NIFI-10804:
-----------------------------
Summary: Update okhttp-digest to version 2.7
Key: NIFI-10804
URL: https://issues.apache.org/jira/browse/NIFI-10804
Project: Apache NiFi
Issue Type: Improvement
Affects Versions: 1.18.0
Reporter: Mike R
The version of okhttp-digest used in the NiFi lookup services is outdated and should be updated to remediate [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]
The current version used there is 2.5, with the most recent version being 2.7. Release notes https://github.com/rburgst/okhttp-digest/blob/2.7/release-notes.md
--
This message was sent by Atlassian Jira
(v8.20.10#820010)