David Handermann created NIFI-11356:
---------------------------------------
Summary: Upgrade Nimbus JOSE JWT to 9.31
Key: NIFI-11356
URL: https://issues.apache.org/jira/browse/NIFI-11356
Project: Apache NiFi
Issue Type: Improvement
Components: Core Framework, Extensions, NiFi Registry
Reporter: David Handermann
Assignee: David Handermann
Nimbus JOSE JWT version 9 prior to 9.24.0 include a shaded version of JSON
Smart 2.4.8, which is vulnerable to resource exhaustion as described in
[CVE-2023-1370|https://nvd.nist.gov/vuln/detail/CVE-2023-1370]. More recent
versions of Nimbus JOSE JWT depend on Gson and are not subject to the
vulnerability.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)