7.5
CVSS V3
Status
Impact
The fix for this CVE requires upgrading netty-codec-compression to 4.2.5.Final. However, this dependency is bundled as part of the AWS extension JAR and cannot be independently updated through dependency management. We need to wait for Apache NiFi 2.6.0 to be officially released before we can apply this security fix.
Status