<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Log4j2 vulnerability in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Log4j2-vulnerability/m-p/333732#M231493</link>
    <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;Currently we are using Apache kafka 2.13-2.6.0 Version in our production and Currently (log4j-1.2.17) is installed on the server.&lt;/P&gt;&lt;P&gt;After a recent security scan, our vendor suggested upgrading to Log4j version 2.16.0 or higher since 1.x is an Unsupported Version(end of life) and a CVE-2021-4104 vulnerability.&lt;/P&gt;&lt;P&gt;Could you please suggest and provide the guidance to upgrade the log4j version at the earliest.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jan 2022 08:06:57 GMT</pubDate>
    <dc:creator>naveennn</dc:creator>
    <dc:date>2022-01-13T08:06:57Z</dc:date>
    <item>
      <title>Log4j2 vulnerability</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Log4j2-vulnerability/m-p/333732#M231493</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;Currently we are using Apache kafka 2.13-2.6.0 Version in our production and Currently (log4j-1.2.17) is installed on the server.&lt;/P&gt;&lt;P&gt;After a recent security scan, our vendor suggested upgrading to Log4j version 2.16.0 or higher since 1.x is an Unsupported Version(end of life) and a CVE-2021-4104 vulnerability.&lt;/P&gt;&lt;P&gt;Could you please suggest and provide the guidance to upgrade the log4j version at the earliest.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 08:06:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Log4j2-vulnerability/m-p/333732#M231493</guid>
      <dc:creator>naveennn</dc:creator>
      <dc:date>2022-01-13T08:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j2 vulnerability</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Log4j2-vulnerability/m-p/333745#M231498</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/94992"&gt;@naveennn&lt;/a&gt;, Please read the relevant Support Announcement here:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cloudera.com/t5/Support-Announcements/Cloudera-response-to-CVE-2021-4104/ba-p/332287" target="_blank" rel="nofollow noopener"&gt;Cloudera response to CVE-2021-4104&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;which also has information on what steps to take.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 10:41:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Log4j2-vulnerability/m-p/333745#M231498</guid>
      <dc:creator>VidyaSargur</dc:creator>
      <dc:date>2022-01-13T10:41:36Z</dc:date>
    </item>
  </channel>
</rss>

