Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-5957

74 high severity CVEs in nifi 1.8.0 - third party dependency libraries

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Invalid
    • 1.5.0, 1.6.0, 1.7.0, 1.8.0, 1.7.1
    • None
    • Core Framework, Security
    • Inserted OWASP Dependency Check plugin into nifi pom.xml & ran report

    Description

      There are 74 High severity CVEs in nifi 1.8.0 according to OWASP Dependency check.

      There is a possibility of a few false positives with this report, /but/ there is the commons-collections:commons-collections:3.2.1 issue which there is proof-of-concept exploit code out for for three years.    These dependencies need to be cleaned up.

      Attachments

        Activity

          People

            Unassigned Unassigned
            ABakerIII Albert Baker
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: