[
https://issues.apache.org/jira/browse/NIFI-10080?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17545097#comment-17545097
]
Joe Witt commented on NIFI-10080:
---------------------------------
[~msr1716] We appreciate you flagging these and playing along with the
specificity. In here too can you please provide links in the tree to where it
exists. Thanks
> Upgrade Vulnerable esapi dependency
> ------------------------------------
>
> Key: NIFI-10080
> URL: https://issues.apache.org/jira/browse/NIFI-10080
> Project: Apache NiFi
> Issue Type: Bug
> Affects Versions: 1.16.1, 1.16.2
> Reporter: Mike R
> Priority: Major
>
> The ESAPI software found at esapi-2.2.0.0.jar has 2 vulnerabilities in it
> that affect all versions below 2.3.0.0. Updating will remove the
> vulnerabilities
> # [CVE-2022-23457|https://github.com/advisories/GHSA-8m5h-hrqm-pxm2]
> # [CVE-2022-24891|https://github.com/advisories/GHSA-q77q-vx4q-xx6q]
--
This message was sent by Atlassian Jira
(v8.20.7#820007)