[
https://issues.apache.org/jira/browse/NIFI-10060?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17542626#comment-17542626
]
Joe Witt commented on NIFI-10060:
---------------------------------
gson we will deal with as we have several reports in for that one.
nifi xml processing is our own lib and we did fix cve's there recently. but
we're not reporting any issue there now so that is a false positive.
protobuf-java just needs someone to look into it most likely.
There are a ton more libs than this which have some CVE reported against them.
We take action pre-emptively when we can but for many things it isn't that easy
and we often aren't actually vulnerable to the vulnerability referenced.
Thanks
> Fix Issues Found In Dependency Checker
> --------------------------------------
>
> Key: NIFI-10060
> URL: https://issues.apache.org/jira/browse/NIFI-10060
> Project: Apache NiFi
> Issue Type: Bug
> Affects Versions: 1.16.1, 1.16.2
> Reporter: Mike R
> Priority: Major
>
> Dependencychecker by OWASP shows the following dependencies that have CVEs
> against them and are showing as vulnerable when I implement NiFi in my
> environment when it gets scanned. Are there any plans to upgrade any of the
> following:
> protobuf-java-3.19.1.jar
> nifi-xml-processing-1.16.2.jar
> google-http-client-gson-1.140.1.jar
--
This message was sent by Atlassian Jira
(v8.20.7#820007)