Re: CVE-2022-22965: Spring RCE

2022-03-31 Thread Tristan Steele
Hi David, Thanks very much for the detailed response, good to know this one shouldn't be a problem for NiFi. Cheers, Tristan On Fri, Apr 1, 2022 at 1:15 PM David Handermann wrote: > Hi Tristan, > > Although NiFi 1.15.3 and earlier include Spring Framework libraries > identified with

Re: PR Review

2022-03-31 Thread Joe Witt
Approved the workflow run.Should no longer be needed once stuff is merged. I think it does this for PRs until at least one commit is found. Thanks On Thu, Mar 31, 2022 at 5:00 PM Pat Alwell, III wrote: > Hey Folks! > > I have an open PR for a small bug fix and I don’t want it to get lost

Re: CVE-2022-22965: Spring RCE

2022-03-31 Thread David Handermann
Hi Tristan, Although NiFi 1.15.3 and earlier include Spring Framework libraries identified with CVE-2022-22965, initial research suggests that NiFi is not impacted. NiFi and NiFi Registry use Jetty, whereas the vulnerability requires running applications on Apache Tomcat. The vulnerability also

CVE-2022-22965: Spring RCE

2022-03-31 Thread Tristan Steele
Good Day, I've been reading through some of the information that is now available about the recently reported remote code execution vulnerability in the Spring framework and it appears that a vulnerable version of this library is part of the 1.15.3 release? Is it known yet if this library is

Re: Slack Invite

2022-03-31 Thread Marton Szasz
Hi, You can find the invite line near the bottom of the Mailing Lists and Chat page of the NiFi website. https://nifi.apache.org/mailing_lists.html Regards, Marton On Fri, 1 Apr 2022 at 00:19, Pat Alwell, III wrote: > > Hey Folks, > > Trying to get access to the NiFi slack channel, but the

Slack Invite

2022-03-31 Thread Pat Alwell, III
Hey Folks, Trying to get access to the NiFi slack channel, but the link in the README.md for NiFi hosted on Github doesn’t seem to generate a sign up token. Can anyone provide that link? Please advise. -Pat

PR Review

2022-03-31 Thread Pat Alwell, III
Hey Folks! I have an open PR for a small bug fix and I don’t want it to get lost in limbo. Can someone please take a look when you have a chance? https://github.com/apache/nifi/pull/5905 It's a simple enough change, so I don’t see the approval taking more than a few minutes. Need to run