7.5
CVSS CVSS_V3
Status
Impact
The fix for this CVE requires upgrading netty-codec-http to 4.2.5.Final. However, this dependency is bundled as part of the AWS extension JAR and cannot be independently updated through dependency management. We need to wait for Apache NiFi 2.6.0 to be officially released before we can apply this security fix.
Status