Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-10716

Upgrade Flume to 1.11.0

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • None
    • 1.19.0
    • None

    Description

      The Flume Processors depend on Flume 1.10.1, which is vulnerable to CVE-2022-42468.

      Although trigger the vulnerability requires a Flume configuration that includes the JMS Source with an unsafe provider URL, the dependency should be upgraded to 1.11.0 in order to mitigate potential configuration issues.

      Attachments

        Issue Links

          Activity

            People

              exceptionfactory David Handermann
              exceptionfactory David Handermann
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 20m
                  20m