Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-11478

Upgrade Spring Framework to 5.3.27 and Spring Security to 5.8.3

    XMLWordPrintableJSON

Details

    Description

      Spring Framework 5.3.26 and earlier contain a Spring Expression Language vulnerability described in CVE-2023-20863.

      Spring Security 5.8.2 and earlier contain a Security Context logout vulnerability described in CVE-2023-20862.

      Spring Framework 5.3.27 resolves CVE-2023-20863 and Spring Security 5.8.3 resolves CVE-2023-20862.

      Spring Boot 2.7.11 incorporates these upgrades and should be updated for Registry.

      Framework components do not use Spring Expression Language and do not use HTTP sessions for persisting Security Context information.

      Attachments

        Issue Links

          Activity

            People

              exceptionfactory David Handermann
              exceptionfactory David Handermann
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 20m
                  20m