<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: log4j2 vulnerability (CVE-2021-44228) in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/334233#M231665</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/95041"&gt;@kevmac&lt;/a&gt;&amp;nbsp;you and&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/70786"&gt;@Eric_B&lt;/a&gt;&amp;nbsp;can find out about the actual target Log4j library version for Cloudera's suggested remediation by consulting the blog post &lt;A href="https://blog.cloudera.com/cloudera-response-to-cve-2021-44228/" target="_blank" rel="noopener"&gt;Cloudera Response to CVE-2021-44228&lt;/A&gt;. The version of the Log4j library that the aforementioned remediation script is intended for is specified in the very first paragraph, sub-headed &lt;EM&gt;Summary&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jan 2022 19:49:03 GMT</pubDate>
    <dc:creator>ask_bill_brooks</dc:creator>
    <dc:date>2022-01-19T19:49:03Z</dc:date>
    <item>
      <title>log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/331987#M231043</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wanted to ask if there's a page / instructions / info regarding the recent log4j2 vulnerability (&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228" target="_blank" rel="noopener"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228&lt;/A&gt;) and how it can affect Cloudera CDH setups? If it does affect, what are the recommended mitigations on it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Mor&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 15:09:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/331987#M231043</guid>
      <dc:creator>MorK</dc:creator>
      <dc:date>2021-12-13T15:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/331990#M231046</link>
      <description>&lt;P&gt;It is in deed an important question.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 09:41:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/331990#M231046</guid>
      <dc:creator>MartinTerreni</dc:creator>
      <dc:date>2021-12-12T09:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/331999#M231053</link>
      <description>&lt;P&gt;Following - Cloudera please provide recommendations as this is really urgent.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 21:33:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/331999#M231053</guid>
      <dc:creator>RajeshTripathy</dc:creator>
      <dc:date>2021-12-12T21:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332004#M231055</link>
      <description>&lt;P&gt;Please go through below apache docs, its might help&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://logging.apache.org/log4j/2.x/manual/migration.html" target="_blank"&gt;https://logging.apache.org/log4j/2.x/manual/migration.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 03:26:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332004#M231055</guid>
      <dc:creator>Shahrukh</dc:creator>
      <dc:date>2021-12-13T03:26:21Z</dc:date>
    </item>
    <item>
      <title>CVE-2021-44228 - log4j Arbitrary RCE</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332049#M231073</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any impact of&amp;nbsp;CVE-2021-44228 - log4j Arbitrary RCE on CDH 5.x and 6.x??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hanu&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 07:30:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332049#M231073</guid>
      <dc:creator>Hanumantha</dc:creator>
      <dc:date>2021-12-13T07:30:59Z</dc:date>
    </item>
    <item>
      <title>Regarding log4j CVE-2021-44228</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332071#M231078</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currenlty in our organization we are using Cloudera 6.3.1 express edition, recently our company security team came up with&amp;nbsp;log4j CVE-2021-44228&amp;nbsp; vulnerable, Could you please suggest due to this any problem for cloudera ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Srikanth&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 09:41:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332071#M231078</guid>
      <dc:creator>sri840</dc:creator>
      <dc:date>2021-12-13T09:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding log4j CVE-2021-44228</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332072#M231079</link>
      <description>&lt;P&gt;I second this question. I currently administer a CDH 5.16 cluster that we're in the process of upgrading to CDP 7.x. Is there a statement from cloudera about the extent of the vulnerablility in their products and how we can go about patching it?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 10:04:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332072#M231079</guid>
      <dc:creator>ThomasHopewell</dc:creator>
      <dc:date>2021-12-13T10:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding log4j CVE-2021-44228</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332074#M231080</link>
      <description>&lt;P&gt;Hi Thomas&lt;A href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31772" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you please refer to below url , this statement came from apache, but not from Cloudera.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="noopener"&gt;https://logging.apache.org/log4j/2.x/security.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Srikanth&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 10:19:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332074#M231080</guid>
      <dc:creator>sri840</dc:creator>
      <dc:date>2021-12-13T10:19:28Z</dc:date>
    </item>
    <item>
      <title>Remote code injection in Log4j affect on NIFI</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332076#M231083</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a vulnerability reported for Log4J in in the below link:-&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/advisories/GHSA-jfh8-c2jp-5v3q" target="_blank" rel="noopener"&gt;https://github.com/advisories/GHSA-jfh8-c2jp-5v3q&lt;/A&gt;&lt;/P&gt;&lt;P&gt;As per our knowledge, NIFI uses LOGback which is a successor of Log4J, so we should not be having any issues/vulnerabilities with NIFI. But, we wanted to be sure of the same. Please share if in case anyone has any thoughts for NIFI over this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using NIFI 1.8 currently in our organization which uses Logback 1.1.3&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 10:58:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332076#M231083</guid>
      <dc:creator>gauravsuri</dc:creator>
      <dc:date>2021-12-13T10:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding log4j CVE-2021-44228</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332086#M231081</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Srikanth,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for that, it's a helpful link.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It would still be great to get something offical from Cloudera. I've emailed our rep with them to see if he has any info. If he gets back to me, I'll drop anything relevant back into this thread.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 13:54:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332086#M231081</guid>
      <dc:creator>ThomasHopewell</dc:creator>
      <dc:date>2021-12-13T13:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228 - log4j Arbitrary RCE</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332087#M231075</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Cloudera platform security teams are actively assessing the impact to our on-premises and cloud&amp;nbsp;&amp;nbsp;products and will provide an impact analysis update to customers as soon as possible.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 13:59:27 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332087#M231075</guid>
      <dc:creator>cjervis</dc:creator>
      <dc:date>2021-12-13T13:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332101#M231084</link>
      <description>&lt;P&gt;Hive I believe is vulnerable and running 2.10.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 16:26:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332101#M231084</guid>
      <dc:creator>Eric_B</dc:creator>
      <dc:date>2021-12-13T16:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332113#M231089</link>
      <description>&lt;P&gt;I'm also curious about hive, not sure how to remediate.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 19:00:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332113#M231089</guid>
      <dc:creator>dward4</dc:creator>
      <dc:date>2021-12-13T19:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332114#M231090</link>
      <description>&lt;P&gt;Obviously, the best solution would be to replace all jars with the latest Log4j2 jars, but the way Cloudera does things now it might break things. In the long term, better to wait for them to make a statement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a link that may help, look under workarounds:&amp;nbsp;&lt;A href="https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/" target="_blank"&gt;https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 19:04:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332114#M231090</guid>
      <dc:creator>Eric_B</dc:creator>
      <dc:date>2021-12-13T19:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332115#M231091</link>
      <description>&lt;P&gt;I noticed this new repo on Cloudera's GitHub but have not seen any official communication about it on Cloudera's site, from our account team, or via the proactive support channels - that makes me leery about using it in our environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/cloudera/cloudera-scripts-for-log4j" target="_blank"&gt;https://github.com/cloudera/cloudera-scripts-for-log4j&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 19:09:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332115#M231091</guid>
      <dc:creator>jimcovert</dc:creator>
      <dc:date>2021-12-13T19:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332116#M231092</link>
      <description>&lt;P&gt;Agreed. Glad to see anything being done, but an official message needs to be put out before I destroy production lol.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 19:15:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332116#M231092</guid>
      <dc:creator>Eric_B</dc:creator>
      <dc:date>2021-12-13T19:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332119#M231095</link>
      <description>&lt;P&gt;All, please read the Cloudera blog article on this topic:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://blog.cloudera.com/cloudera-response-to-cve-2021-4428/" target="_blank" rel="noopener"&gt;Cloudera Response to CVE-2021-4428&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 19:58:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332119#M231095</guid>
      <dc:creator>cjervis</dc:creator>
      <dc:date>2021-12-13T19:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332130#M231097</link>
      <description>&lt;P&gt;Latest Cloudera Hive JDBC driver 2.6.15 contains shaded log4j2 v2.13.3 (according to pom.xml in META-INF/maven/org.apache.logging.log4j/log4j-core)&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 20:28:27 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332130#M231097</guid>
      <dc:creator>Baxy</dc:creator>
      <dc:date>2021-12-13T20:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332145#M231101</link>
      <description>&lt;P&gt;The&amp;nbsp;&lt;SPAN&gt;TSB is not available unless you have a Knowledge Base subscription. Given the severity of the problem, will this information be made available to the public?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 21:47:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332145#M231101</guid>
      <dc:creator>Eric_B</dc:creator>
      <dc:date>2021-12-13T21:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: log4j2 vulnerability (CVE-2021-44228)</title>
      <link>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332146#M231102</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/70786"&gt;@Eric_B&lt;/a&gt;&amp;nbsp;Yes. There is a link for non-customers of Cloudera in &lt;A href="https://blog.cloudera.com/cloudera-response-to-cve-2021-4428/" target="_self"&gt;the blog article&lt;/A&gt; linked above. It's at the end of the paragraph beginning "What Cloudera products and versions are affected?"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VidyaSargur_0-1639464383654.png" style="width: 558px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/33019i807E943948740A5A/image-dimensions/558x145?v=v2" width="558" height="145" role="button" title="VidyaSargur_0-1639464383654.png" alt="VidyaSargur_0-1639464383654.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 06:46:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/log4j2-vulnerability-CVE-2021-44228/m-p/332146#M231102</guid>
      <dc:creator>ask_bill_brooks</dc:creator>
      <dc:date>2021-12-14T06:46:45Z</dc:date>
    </item>
  </channel>
</rss>

