<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: does CVE-2020-9492 fixed in HDP 2.6.5 in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/does-CVE-2020-9492-fixed-in-HDP-2-6-5/m-p/327867#M230174</link>
    <description>&lt;P&gt;Yes, if the version is supported. But as per&amp;nbsp;&lt;A href="https://www.cloudera.com/legal/policies/support-lifecycle-policy.html" target="_blank"&gt;https://www.cloudera.com/legal/policies/support-lifecycle-policy.html&lt;/A&gt;&amp;nbsp;the support is already ended for HDP 2.6.5.&lt;/P&gt;&lt;P&gt;So, I would recommend upgrading the cluster to CDP for the latest features and security fixes.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Oct 2021 10:19:28 GMT</pubDate>
    <dc:creator>nthomas</dc:creator>
    <dc:date>2021-10-18T10:19:28Z</dc:date>
    <item>
      <title>does CVE-2020-9492 fixed in HDP 2.6.5</title>
      <link>https://community.cloudera.com/t5/Support-Questions/does-CVE-2020-9492-fixed-in-HDP-2-6-5/m-p/327854#M230169</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I found this new CVE for Hadoop (CVE-2020-9492).&lt;BR /&gt;The solution is to upgrade to Hadoop 2.10.1 but HDP 2.6.5 (with Apache Hadoop version 2.6.7) is the latest version of Apache Hadoop 2.&lt;/P&gt;&lt;P&gt;Could be possible to fix any CVE into HDP 2.6.5.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 07:58:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/does-CVE-2020-9492-fixed-in-HDP-2-6-5/m-p/327854#M230169</guid>
      <dc:creator>jeromedruais</dc:creator>
      <dc:date>2021-10-18T07:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: does CVE-2020-9492 fixed in HDP 2.6.5</title>
      <link>https://community.cloudera.com/t5/Support-Questions/does-CVE-2020-9492-fixed-in-HDP-2-6-5/m-p/327862#M230170</link>
      <description>&lt;P&gt;I dont see any fix for your version. However, you can use the below workaround:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If https is enabled which encrypts and authenticates the peer then it’s not an issue. Make sure dfs.http.policy in hdfs-site.xml = HTTPS_ONLY&lt;BR /&gt;refer:&amp;nbsp;&lt;A href="https://my.cloudera.com/knowledge/TSB-2021-406-CVE-2020-9492-Hadoop-filesystem-bindings-ie?id=312034" target="_blank"&gt;https://my.cloudera.com/knowledge/TSB-2021-406-CVE-2020-9492-Hadoop-filesystem-bindings-ie?id=312034&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 18 Oct 2021 09:12:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/does-CVE-2020-9492-fixed-in-HDP-2-6-5/m-p/327862#M230170</guid>
      <dc:creator>nthomas</dc:creator>
      <dc:date>2021-10-18T09:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: does CVE-2020-9492 fixed in HDP 2.6.5</title>
      <link>https://community.cloudera.com/t5/Support-Questions/does-CVE-2020-9492-fixed-in-HDP-2-6-5/m-p/327865#M230172</link>
      <description>&lt;P&gt;Thanks for the asnwer regarding this security issue.&lt;/P&gt;&lt;P&gt;Generally speaking, does Cloudera could include future fixes in an old version ?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 10:12:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/does-CVE-2020-9492-fixed-in-HDP-2-6-5/m-p/327865#M230172</guid>
      <dc:creator>jeromedruais</dc:creator>
      <dc:date>2021-10-18T10:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: does CVE-2020-9492 fixed in HDP 2.6.5</title>
      <link>https://community.cloudera.com/t5/Support-Questions/does-CVE-2020-9492-fixed-in-HDP-2-6-5/m-p/327867#M230174</link>
      <description>&lt;P&gt;Yes, if the version is supported. But as per&amp;nbsp;&lt;A href="https://www.cloudera.com/legal/policies/support-lifecycle-policy.html" target="_blank"&gt;https://www.cloudera.com/legal/policies/support-lifecycle-policy.html&lt;/A&gt;&amp;nbsp;the support is already ended for HDP 2.6.5.&lt;/P&gt;&lt;P&gt;So, I would recommend upgrading the cluster to CDP for the latest features and security fixes.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 10:19:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/does-CVE-2020-9492-fixed-in-HDP-2-6-5/m-p/327867#M230174</guid>
      <dc:creator>nthomas</dc:creator>
      <dc:date>2021-10-18T10:19:28Z</dc:date>
    </item>
  </channel>
</rss>

