[
https://issues.apache.org/jira/browse/NIFI-10694?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17625964#comment-17625964
]
David Handermann commented on NIFI-10694:
-----------------------------------------
NiFi Registry does not have any direct dependencies on Apache Commons Text. The
NiFi Toolkit works with NiFi Registry, but NiFi Registry itself does not
contain the library.
All NiFi components have been upgraded to Apache Commons Text 1.10.0 under
NIFI-10648, so the next project release will apply to all subprojects,
including the NiFi Toolkit.
> Does CVE-2022-42889 affect Nifi Registry ?
> ------------------------------------------
>
> Key: NIFI-10694
> URL: https://issues.apache.org/jira/browse/NIFI-10694
> Project: Apache NiFi
> Issue Type: Task
> Reporter: Wesley Philip
> Priority: Major
>
> Nifi Registry 17 contains this library:
>
> /opt/nifi/nifi-toolkit-current/lib/commons-text-1.8.jar
>
> Is Nifi Registry affected, and are their plans to address this CVE?
--
This message was sent by Atlassian Jira
(v8.20.10#820010)