Author: thenatog
Date: Thu Dec 16 23:40:37 2021
New Revision: 1896080

URL: http://svn.apache.org/viewvc?rev=1896080&view=rev
Log:
Updated NiFi Security page for 1.15.1

Modified:
    nifi/site/trunk/download.html
    nifi/site/trunk/minifi/download.html
    nifi/site/trunk/registry.html
    nifi/site/trunk/security.html

Modified: nifi/site/trunk/download.html
URL: 
http://svn.apache.org/viewvc/nifi/site/trunk/download.html?rev=1896080&r1=1896079&r2=1896080&view=diff
==============================================================================
--- nifi/site/trunk/download.html (original)
+++ nifi/site/trunk/download.html Thu Dec 16 23:40:37 2021
@@ -129,30 +129,30 @@
     <div class="large-12 columns">
         <h2>Releases</h2>
         <ul>
-            <li><h3>1.15.1</h3>
+            <li><h3>1.15.0</h3>
                 <ul>
-                    <li>Released December 15th, 2021</li>
+                    <li>Released November 7th, 2021</li>
                     <li>
                         Sources:
                         <ul>
-                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/nifi-1.15.1-source-release.zip";>nifi-1.15.1-source-release.zip</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-1.15.1-source-release.zip.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-1.15.1-source-release.zip.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-1.15.1-source-release.zip.sha512";>sha512</a>
 )</li>
+                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/nifi-1.15.0-source-release.zip";>nifi-1.15.0-source-release.zip</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-1.15.0-source-release.zip.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-1.15.0-source-release.zip.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-1.15.0-source-release.zip.sha512";>sha512</a>
 )</li>
                         </ul>
                     </li>
                     <li>
                         Binaries
                         <ul>
-                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/nifi-1.15.1-bin.tar.gz";>nifi-1.15.1-bin.tar.gz</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-1.15.1-bin.tar.gz.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-1.15.1-bin.tar.gz.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-1.15.1-bin.tar.gz.sha512";>sha512</a>
 )</li>
+                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/nifi-1.15.0-bin.tar.gz";>nifi-1.15.0-bin.tar.gz</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-1.15.0-bin.tar.gz.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-1.15.0-bin.tar.gz.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-1.15.0-bin.tar.gz.sha512";>sha512</a>
 )</li>
 
-                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/nifi-1.15.1-bin.zip";>nifi-1.15.1-bin.zip</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-1.15.1-bin.zip.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-1.15.1-bin.zip.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-1.15.1-bin.zip.sha512";>sha512</a>
 )</li>
+                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/nifi-1.15.0-bin.zip";>nifi-1.15.0-bin.zip</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-1.15.0-bin.zip.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-1.15.0-bin.zip.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-1.15.0-bin.zip.sha512";>sha512</a>
 )</li>
 
 
-                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/nifi-toolkit-1.15.1-bin.tar.gz";>nifi-toolkit-1.15.1-bin.tar.gz</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-toolkit-1.15.1-bin.tar.gz.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-toolkit-1.15.1-bin.tar.gz.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-toolkit-1.15.1-bin.tar.gz.sha512";>sha512</a>
 )</li>
+                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/nifi-toolkit-1.15.0-bin.tar.gz";>nifi-toolkit-1.15.0-bin.tar.gz</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-toolkit-1.15.0-bin.tar.gz.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-toolkit-1.15.0-bin.tar.gz.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-toolkit-1.15.0-bin.tar.gz.sha512";>sha512</a>
 )</li>
 
-                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/nifi-toolkit-1.15.1-bin.zip";>nifi-toolkit-1.15.1-bin.zip</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-toolkit-1.15.1-bin.zip.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-toolkit-1.15.1-bin.zip.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-toolkit-1.15.1-bin.zip.sha512";>sha512</a>
 )</li>
-                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/nifi-stateless-1.15.1-bin.tar.gz";>nifi-stateless-1.15.1-bin.tar.gz</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-stateless-1.15.1-bin.tar.gz.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-stateless-1.15.1-bin.tar.gz.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-stateless-1.15.1-bin.tar.gz.sha512";>sha512</a>
 )</li>
+                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/nifi-toolkit-1.15.0-bin.zip";>nifi-toolkit-1.15.0-bin.zip</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-toolkit-1.15.0-bin.zip.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-toolkit-1.15.0-bin.zip.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-toolkit-1.15.0-bin.zip.sha512";>sha512</a>
 )</li>
+                            <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/nifi-stateless-1.15.0-bin.tar.gz";>nifi-stateless-1.15.0-bin.tar.gz</a>
 ( <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-stateless-1.15.0-bin.tar.gz.asc";>asc</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-stateless-1.15.0-bin.tar.gz.sha256";>sha256</a>,
 <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-stateless-1.15.0-bin.tar.gz.sha512";>sha512</a>
 )</li>
                         </ul>
                     </li>
-                    <li><a 
href="https://cwiki.apache.org/confluence/display/NIFI/Release+Notes#ReleaseNotes-Version1.15.1";>Release
 Notes</a></li>
+                    <li><a 
href="https://cwiki.apache.org/confluence/display/NIFI/Release+Notes#ReleaseNotes-Version1.15.0";>Release
 Notes</a></li>
                     <li><a 
href="https://cwiki.apache.org/confluence/display/NIFI/Migration+Guidance";>Migration
 Guidance</a></li>
                 </ul>
             </li>

Modified: nifi/site/trunk/minifi/download.html
URL: 
http://svn.apache.org/viewvc/nifi/site/trunk/minifi/download.html?rev=1896080&r1=1896079&r2=1896080&view=diff
==============================================================================
--- nifi/site/trunk/minifi/download.html (original)
+++ nifi/site/trunk/minifi/download.html Thu Dec 16 23:40:37 2021
@@ -123,7 +123,7 @@
         <h2>Releases</h2>
         <h3>MiNiFi (Java)</h3>
         <ul>
-          <li>1.15.1
+          <li>1.15.0
               <ul>
                       Sources:
                       <ul>
@@ -134,17 +134,17 @@
                   <li>
                       Binaries
                       <ul>
-                          <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/minifi-1.15.1-bin.tar.gz";>minifi-1.15.1-bin.tar.gz</a>
-                            ( <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-1.15.1-bin.tar.gz.asc";>asc</a>,
-                              <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-1.15.1-bin.tar.gz.sha256";>sha256</a>
 )
-                          </li>
-                          <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/minifi-1.15.1-bin.zip";>minifi-1.15.1-bin.zip</a>
-                            ( <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-1.15.1-bin.zip.asc";>asc</a>,
-                              <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-1.15.1-bin.zip.sha256";>sha256</a>
 )
+                          <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/minifi-1.15.0-bin.tar.gz";>minifi-1.15.0-bin.tar.gz</a>
+                            ( <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-1.15.0-bin.tar.gz.asc";>asc</a>,
+                              <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-1.15.0-bin.tar.gz.sha256";>sha256</a>
 )
+                          </li>
+                          <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/minifi-1.15.0-bin.zip";>minifi-1.15.0-bin.zip</a>
+                            ( <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-1.15.0-bin.zip.asc";>asc</a>,
+                              <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-1.15.0-bin.zip.sha256";>sha256</a>
 )
                       </ul>
                   </li>
 
-                  <li><a 
href="https://cwiki.apache.org/confluence/display/MINIFI/Release+Notes#ReleaseNotes-Version1.15.1";>Release
 Notes</a></li>
+                  <li><a 
href="https://cwiki.apache.org/confluence/display/MINIFI/Release+Notes#ReleaseNotes-Version1.15.0";>Release
 Notes</a></li>
               </ul>
           </li>
         </ul>
@@ -217,32 +217,32 @@
         </ul>
         <h3>MiNiFi Toolkit Binaries</h3>
         <ul>
-          <li>1.15.1 
+          <li>1.15.0 
             <ul>
               <li>
-                <a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/minifi-toolkit-1.15.1-bin.tar.gz";>minifi-toolkit-1.15.1-bin.tar.gz</a>
-                ( <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-toolkit-1.15.1-bin.tar.gz.asc";>asc</a>,
-                  <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-toolkit-1.15.1-bin.tar.gz.sha256";>sha256</a>
 )
+                <a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/minifi-toolkit-1.15.0-bin.tar.gz";>minifi-toolkit-1.15.0-bin.tar.gz</a>
+                ( <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-toolkit-1.15.0-bin.tar.gz.asc";>asc</a>,
+                  <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-toolkit-1.15.0-bin.tar.gz.sha256";>sha256</a>
 )
               </li>
-              <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/minifi-toolkit-1.15.1-bin.zip";>minifi-toolkit-1.15.1-bin.zip</a>
-                ( <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-toolkit-1.15.1-bin.zip.asc";>asc</a>,
-                  <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-toolkit-1.15.1-bin.zip.sha256";>sha256</a>
 )
+              <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/minifi-toolkit-1.15.0-bin.zip";>minifi-toolkit-1.15.0-bin.zip</a>
+                ( <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-toolkit-1.15.0-bin.zip.asc";>asc</a>,
+                  <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-toolkit-1.15.0-bin.zip.sha256";>sha256</a>
 )
               </li>
             </ul>
           </li>
         </ul>
         <h3>MiNiFi Command and Control Server Binaries</h3>
         <ul>
-          <li>1.15.1
+          <li>1.15.0
             <ul>
               <li>
-                <a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/minifi-c2-1.15.1-bin.tar.gz";>minifi-c2-1.15.1-bin.tar.gz</a>
-                ( <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-c2-1.15.1-bin.tar.gz.asc";>asc</a>,
-                  <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-c2-1.15.1-bin.tar.gz.sha256";>sha256</a>
 )
+                <a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/minifi-c2-1.15.0-bin.tar.gz";>minifi-c2-1.15.0-bin.tar.gz</a>
+                ( <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-c2-1.15.0-bin.tar.gz.asc";>asc</a>,
+                  <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-c2-1.15.0-bin.tar.gz.sha256";>sha256</a>
 )
               </li>
-              <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/minifi-c2-1.15.1-bin.zip";>minifi-c2-1.15.1-bin.zip</a>
-                ( <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-c2-1.15.1-bin.zip.asc";>asc</a>,
-                  <a 
href="https://downloads.apache.org/nifi/1.15.1/minifi-c2-1.15.1-bin.zip.sha256";>sha256</a>
 )
+              <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/minifi-c2-1.15.0-bin.zip";>minifi-c2-1.15.0-bin.zip</a>
+                ( <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-c2-1.15.0-bin.zip.asc";>asc</a>,
+                  <a 
href="https://downloads.apache.org/nifi/1.15.0/minifi-c2-1.15.0-bin.zip.sha256";>sha256</a>
 )
               </li>
             </ul>
           </li>

Modified: nifi/site/trunk/registry.html
URL: 
http://svn.apache.org/viewvc/nifi/site/trunk/registry.html?rev=1896080&r1=1896079&r2=1896080&view=diff
==============================================================================
--- nifi/site/trunk/registry.html (original)
+++ nifi/site/trunk/registry.html Thu Dec 16 23:40:37 2021
@@ -172,7 +172,7 @@
               </p>
               <ul>
                   <li>
-                      1.15.1
+                      1.15.0
                       <ul>
                           <li>
                               Sources
@@ -183,18 +183,18 @@
                           <li>
                               Binaries
                               <ul>
-                                  <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/nifi-registry-1.15.1-bin.tar.gz";>nifi-registry-1.15.1-bin.tar.gz</a>
 (
-                                      <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-registry-1.15.1-bin.tar.gz.asc";>asc</a>,
-                                      <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-registry-1.15.1-bin.tar.gz.sha256";>sha256</a>,
-                                      <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-registry-1.15.1-bin.tar.gz.sha512";>sha512</a>
 )</li>
+                                  <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/nifi-registry-1.15.0-bin.tar.gz";>nifi-registry-1.15.0-bin.tar.gz</a>
 (
+                                      <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-registry-1.15.0-bin.tar.gz.asc";>asc</a>,
+                                      <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-registry-1.15.0-bin.tar.gz.sha256";>sha256</a>,
+                                      <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-registry-1.15.0-bin.tar.gz.sha512";>sha512</a>
 )</li>
 
-                                  <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.1/nifi-registry-1.15.1-bin.zip";>nifi-registry-1.15.1-bin.zip</a>
 (
-                                      <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-registry-1.15.1-bin.zip.asc";>asc</a>,
-                                      <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-registry-1.15.1-bin.zip.sha256";>sha256</a>,
-                                      <a 
href="https://downloads.apache.org/nifi/1.15.1/nifi-registry-1.15.1-bin.zip.sha512";>sha512</a>
 )</li>
+                                  <li><a 
href="https://www.apache.org/dyn/closer.lua?path=/nifi/1.15.0/nifi-registry-1.15.0-bin.zip";>nifi-registry-1.15.0-bin.zip</a>
 (
+                                      <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-registry-1.15.0-bin.zip.asc";>asc</a>,
+                                      <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-registry-1.15.0-bin.zip.sha256";>sha256</a>,
+                                      <a 
href="https://downloads.apache.org/nifi/1.15.0/nifi-registry-1.15.0-bin.zip.sha512";>sha512</a>
 )</li>
                               </ul>
                           </li>
-                          <li><a 
href="https://cwiki.apache.org/confluence/display/NIFI/Release+Notes#ReleaseNotes-Version1.15.1";>Release
 Notes</a></li>
+                          <li><a 
href="https://cwiki.apache.org/confluence/display/NIFI/Release+Notes#ReleaseNotes-Version1.15.0";>Release
 Notes</a></li>
                       </ul>
                   </li>
               </ul>

Modified: nifi/site/trunk/security.html
URL: 
http://svn.apache.org/viewvc/nifi/site/trunk/security.html?rev=1896080&r1=1896079&r2=1896080&view=diff
==============================================================================
--- nifi/site/trunk/security.html (original)
+++ nifi/site/trunk/security.html Thu Dec 16 23:40:37 2021
@@ -157,6 +157,67 @@
         <p>Thank you for helping keep Apache NiFi and our users safe!</p>
     </div>
 </div>
+
+<div class="medium-space"></div>
+<div class="row">
+    <div class="large-12 columns features">
+        <h2><a id="1.15.1" href="#1.15.1">Fixed in Apache NiFi 1.15.1</a></h2>
+    </div>
+</div>
+<!-- Vulnerabilities -->
+<div class="row">
+    <div class="large-12 columns features">
+        <h2><a id="1.15.1-vulnerabilities" 
href="#1.15.1-vulnerabilities">Vulnerabilities</a></h2>
+    </div>
+</div>
+<div class="row" style="background-color: aliceblue">
+    <div class="large-12 columns">
+        <p><a id="CVE-2021-44145" 
href="#CVE-2021-44145"><strong>CVE-2021-44145</strong></a>: Apache NiFi 
information disclosure by XXE in TransformXML</p>
+        <p>Severity: <strong>Low</strong></p>
+        <p>Versions Affected:</p>
+        <ul>
+            <li>Apache NiFi 0.1.0 - 1.15.0</li>
+        </ul>
+        </p>
+        <p>Description: In the TransformXML processor, an authenticated user 
could configure an XSLT file which, if it included malicious external entity 
calls, may reveal sensitive information.</p>
+        <p>Mitigation: The <code>'Secure processing'</code> property will now 
apply to the configured XSLT file as well as flow files being transformed. 
Users running any previous NiFi release should upgrade to the latest release. 
</p>
+        <p>Credit: This issue was discovered by DangKhai at Viettel Cyber 
Security.</p>
+        <p>CVE Link: <a 
href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44145"; 
target="_blank">Mitre Database: CVE-2021-44145</a></p>
+        <p>NiFi Jira: <a 
href="https://issues.apache.org/jira/browse/NIFI-9399"; 
target="_blank">NIFI-9399</a></p>
+        <p>NiFi PR: <a href="https://github.com/apache/nifi/pull/5542"; 
target="_blank">PR 5542</a></p>
+        <p>Released: December 15, 2021</p>
+    </div>
+</div>
+<!-- Dependency Vulnerabilities -->
+<div class="row">
+    <div class="large-12 columns features">
+        <h2><a id="1.15.1-dependency-vulnerabilities" 
href="#1.15.1-dependency-vulnerabilities">Dependency Vulnerabilities</a></h2>
+    </div>
+</div>
+<div class="row">
+    <div class="large-12 columns">
+        <p><a id="CVE-2021-44228" 
href="#CVE-2021-44228"><strong>CVE-2021-44228</strong></a>: Apache NiFi's use 
of log4j</p>
+        <p>Severity: <strong>None</strong></p>
+        <p>Versions Affected:</p>
+        <ul>
+            <li>Apache NiFi 0.1.0 - 1.15.0</li>
+        </ul>
+        </p>
+        <p>Description: For posterity we will note here that Apache NiFi uses 
SLF4J for logging with Logback as the runtime
+            implementation since the project's inception. One of our PMC 
members has written an analysis of NiFi's vulnerability (or lack thereof) here: 
<a 
href="https://exceptionfactory.com/posts/2021/12/14/evaluating-log4shell-and-apache-nifi";>https://exceptionfactory.com/posts/2021/12/14/evaluating-log4shell-and-apache-nifi</a>.
 For more information on the log4j vulnerability, see <a 
href="https://nvd.nist.gov/vuln/detail/CVE-2021-44228"; target="_blank">NIST NVD 
CVE-2021-44228</a>. </p>
+        <p>Mitigation: We have taken measures to ensure that any potential 
instances of log4j brought in by dependencies are overriden to log4j 2.16.0.</p>
+        <p>CVE Link: <a 
href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228"; 
target="_blank">Mitre Database: CVE-2021-44228</a></p>
+        <p>NiFi Jira: <a 
href="https://issues.apache.org/jira/browse/NIFI-9474"; 
target="_blank">NIFI-9474</a>
+            <br>NiFi Jira: <a 
href="https://issues.apache.org/jira/browse/NIFI-9482"; 
target="_blank">NIFI-9482</a></p>
+        <p>
+        NiFi PR: <a href="https://github.com/apache/nifi/pull/5592"; 
target="_blank">PR 5592</a>
+        <br>NiFi PR: <a href="https://github.com/apache/nifi/pull/5595"; 
target="_blank">PR 5595</a>
+        <br>NiFi PR: <a href="https://github.com/apache/nifi/pull/5598"; 
target="_blank">PR 5598</a>
+        <br>NiFi PR: <a href="https://github.com/apache/nifi/pull/5600"; 
target="_blank">PR 5600</a>
+        </p>
+        <p>Released: December 15, 2021</p>
+    </div>
+</div>
 <div class="medium-space"></div>
 <div class="row">
     <div class="large-12 columns features">
@@ -203,9 +264,6 @@
         <p>Released: February 16, 2021</p>
     </div>
 </div>
-
-
-
 <div class="medium-space"></div>
 <div class="row">
     <div class="large-12 columns features">


Reply via email to