You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@nifi.apache.org by "ASF subversion and git services (Jira)" <ji...@apache.org> on 2022/11/18 13:37:00 UTC

[jira] [Commented] (NIFI-10804) Update okhttp-digest to version 2.7

    [ https://issues.apache.org/jira/browse/NIFI-10804?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17635869#comment-17635869 ] 

ASF subversion and git services commented on NIFI-10804:
--------------------------------------------------------

Commit 2698282615ccf7fad03692badca9e2bceb86ea55 in nifi's branch refs/heads/main from Pierre Villard
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=2698282615 ]

NIFI-10804 - Update okhttp-digest to 2.7

This closes #6681

Signed-off-by: Mike Thomsen <mt...@apache.org>


> Update okhttp-digest to version 2.7
> -----------------------------------
>
>                 Key: NIFI-10804
>                 URL: https://issues.apache.org/jira/browse/NIFI-10804
>             Project: Apache NiFi
>          Issue Type: Improvement
>    Affects Versions: 1.18.0
>            Reporter: Mike R
>            Assignee: Pierre Villard
>            Priority: Minor
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> The version of okhttp-digest used in the NiFi lookup services is outdated and should be updated to remediate [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]
> The current version used there is 2.5, with the most recent version being 2.7. Release notes https://github.com/rburgst/okhttp-digest/blob/2.7/release-notes.md



--
This message was sent by Atlassian Jira
(v8.20.10#820010)