[ 
https://issues.apache.org/jira/browse/NIFI-9954?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17527541#comment-17527541
 ] 

ASF subversion and git services commented on NIFI-9954:
-------------------------------------------------------

Commit 66e5c546f7d155dbfc3382bb2585e698afb8dfe9 in nifi's branch 
refs/heads/support/nifi-1.16 from David Handermann
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=66e5c546f7 ]

NIFI-9954 Upgraded Spring Framework from 5.3.18 to 5.3.19

- Upgraded Spring Security from 5.6.2 to 5.6.3
- Upgraded Log4j 2 from 2.17.1 to 2.17.2
- Upgraded Spring Boot from 2.6.6 to 2.6.7 for NiFi Registry


> Upgrade to Spring Framework 5.3.19 and Spring Boot 2.6.7
> --------------------------------------------------------
>
>                 Key: NIFI-9954
>                 URL: https://issues.apache.org/jira/browse/NIFI-9954
>             Project: Apache NiFi
>          Issue Type: Improvement
>          Components: Core Framework, NiFi Registry
>            Reporter: David Handermann
>            Assignee: David Handermann
>            Priority: Major
>              Labels: dependency-upgrade
>             Fix For: 1.17.0, 1.16.1
>
>          Time Spent: 0.5h
>  Remaining Estimate: 0h
>
> Spring Framework 5.3.19 includes several bug fixes, including a resolution 
> for [CVE-2022-22968|https://tanzu.vmware.com/security/cve-2022-22968], which 
> impacts data binding classes that are not used in regular NiFi framework 
> operations.
> Spring Boot 2.6.7 incorporates Spring Framework 5.3.19 and several other 
> transitive dependency upgrades for NiFi Registry.
> Spring Security 5.6.3 also includes a small number of improvements over the 
> current version of 5.6.2.



--
This message was sent by Atlassian Jira
(v8.20.7#820007)

Reply via email to