[
https://issues.apache.org/jira/browse/NIFI-10082?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17554261#comment-17554261
]
ASF subversion and git services commented on NIFI-10082:
--------------------------------------------------------
Commit d298a3ab83ebfb41e65a9c4f52f5838c17cee74e in nifi's branch
refs/heads/main from UcanInfosec
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=d298a3ab83 ]
NIFI-10082 Upgraded Google libraries BOM to 25.4.0
This closes #6125
Signed-off-by: David Handermann <[email protected]>
> Update Java Protobuf To Most Recent Version
> -------------------------------------------
>
> Key: NIFI-10082
> URL: https://issues.apache.org/jira/browse/NIFI-10082
> Project: Apache NiFi
> Issue Type: Bug
> Affects Versions: 1.16.1, 1.16.2
> Reporter: Mike R
> Priority: Major
> Time Spent: 1h 10m
> Remaining Estimate: 0h
>
> It looks like Java Protobuf that is used is vulnerable per
> [https://github.com/advisories/GHSA-wrvw-hg22-4m67,] which is
> [CVE-2021-22569|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22569]
> *High* - CVSS Score: 7.
> A fix can be found here, but still needs to be compiled [Release Protocol
> Buffers v3.19.2 · protocolbuffers/protobuf (github.com)|[Release Protocol
> Buffers v3.19.2 · protocolbuffers/protobuf
> (github.com)|https://github.com/protocolbuffers/protobuf/releases/tag/v3.19.2]]
> There is an update available, it just needs to be incorporated
>
> |package|package_path|package_type|package_version|fix|
> |protobuf-java-3.19.1|/nifi/lib/properties/protobuf-java-3.19.1.jar|java|3.19.1|3.19.2|
> |protobuf-java-3.19.1|/nifi-toolkit-current/lib/protobuf-java-3.19.1.jar|java|3.19.1|3.19.2|
--
This message was sent by Atlassian Jira
(v8.20.7#820007)