Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created 12-11-2025 02:56 AM
Hello,
I've installed nifi 2.6 registry security - then I've scanned it in AWS Inspector, it shows me the following results:
0 Critical.
12 High.
12 Medium.
Could anyoune confrim the results? And if this is a stable security version?
Created 12-17-2025 05:34 AM
@fy-test
Apache NiFi is only going to be able to address CVEs found in the NiFi-Registry package lib directory files included with the distribution. Any OS/System-level CVEs would need to be addressed by the owner of the platform on which the NIFi-Registry services is being used.
You can find the Apache NiFi Security Reporting here:
https://nifi.apache.org/documentation/security/
You'll find CVEs already addressed in NiFi and NiFi-Registry on the above page. You'll also see how to report any new security vulnerabilities you may discover.
Please help our community grow. If you found any of the suggestions/solutions provided helped you with solving your issue or answering your question, please take a moment to login and click "Accept as Solution" on one or more of them that helped.
Thank you,
Matt
Created 12-11-2025 07:14 AM
Hello @fy-test,
Thanks for being part of our community.
That could be something normal, NiFi Registry 2.6 is a stable version released on September 21st.
https://cwiki.apache.org/confluence/display/NIFI/Release+Notes#ReleaseNotes-Version2.6.0
Now, those results can be true, but the scanner should tell the CVE-XXXX-XXX IDs
With those you can review if they are reported or not.
If you are using CDF you can open a case with Cloudera and report those CVEs for review.
Created 12-16-2025 10:58 AM
Thank you for the guidance. Here are the specific CVEs identified by AWS Inspector in our NiFi Registry 2.6 scan:
High Severity (12):
Medium Severity (12):
Observations:
Questions:
Any guidance would be appreciated.
Created 12-17-2025 05:34 AM
@fy-test
Apache NiFi is only going to be able to address CVEs found in the NiFi-Registry package lib directory files included with the distribution. Any OS/System-level CVEs would need to be addressed by the owner of the platform on which the NIFi-Registry services is being used.
You can find the Apache NiFi Security Reporting here:
https://nifi.apache.org/documentation/security/
You'll find CVEs already addressed in NiFi and NiFi-Registry on the above page. You'll also see how to report any new security vulnerabilities you may discover.
Please help our community grow. If you found any of the suggestions/solutions provided helped you with solving your issue or answering your question, please take a moment to login and click "Accept as Solution" on one or more of them that helped.
Thank you,
Matt