Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-9585

Upgrade H2 to 2.1.210

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 1.16.0
    • None
    • None

    Description

      The H2 embedded database below version 2.1.210 includes multiple associated vulnerabilities related to unsafe XML column handling and other issues.  Multiple NiFi components leverage H2 for local relational data storage. Although NiFi does not appear to have any direct vulnerabilities as a result of issues with H2, upgrading to the latest version will avoid false positive security scans and provide better maintainability.

      Due to related database components such as Flyway in NiFi Registry, upgrading H2 will also require upgrades to related dependencies and services.

      Attachments

        Issue Links

          Activity

            People

              mattyb149 Matt Burgess
              exceptionfactory David Handermann
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 2h 10m
                  2h 10m