[
https://issues.apache.org/jira/browse/NIFI-10804?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17635869#comment-17635869
]
ASF subversion and git services commented on NIFI-10804:
--------------------------------------------------------
Commit 2698282615ccf7fad03692badca9e2bceb86ea55 in nifi's branch
refs/heads/main from Pierre Villard
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=2698282615 ]
NIFI-10804 - Update okhttp-digest to 2.7
This closes #6681
Signed-off-by: Mike Thomsen <[email protected]>
> Update okhttp-digest to version 2.7
> -----------------------------------
>
> Key: NIFI-10804
> URL: https://issues.apache.org/jira/browse/NIFI-10804
> Project: Apache NiFi
> Issue Type: Improvement
> Affects Versions: 1.18.0
> Reporter: Mike R
> Assignee: Pierre Villard
> Priority: Minor
> Time Spent: 10m
> Remaining Estimate: 0h
>
> The version of okhttp-digest used in the NiFi lookup services is outdated and
> should be updated to remediate
> [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]
> The current version used there is 2.5, with the most recent version being
> 2.7. Release notes
> https://github.com/rburgst/okhttp-digest/blob/2.7/release-notes.md
--
This message was sent by Atlassian Jira
(v8.20.10#820010)