Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
Description
Apache HBase 2 has a direct dependency on Protobuf Java 2.5.0, which has multiple known vulnerabilities related to potential resource exhaustion. HBase Protobuf documentation describes changes to Protobuf dependencies for HBase 3, although HBase 3 is still in beta at the time of this writing. Existing NiFi integration with HBase 2 should be removed from the main branch to eliminate vulnerabilities associated with Protobuf Java 2.5.0. Direct support for HBase could be revisited with new versions of HBase.
Attachments
Issue Links
- links to
- mentioned in
-
Page Loading...