<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question CVE-2022-22970 and CVE-2022-22971 spring-core vulnerabilities in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/CVE-2022-22970-and-CVE-2022-22971-spring-core/m-p/356215#M237227</link>
    <description>&lt;P&gt;Our vulnerability scanning found these two vulnerabilities on our CDP Private Cloud 7.1.7-SP1,&amp;nbsp;CVE-2022-22970 and CVE-2022-22971.&amp;nbsp; There are several versions of spring-core in the parcel, none of which are the recommended version:&lt;BR /&gt;&lt;BR /&gt;./jars/spring-core-4.3.29.RELEASE.jar&lt;BR /&gt;./jars/spring-core-5.2.18.RELEASE.jar&lt;BR /&gt;./jars/spring-core-5.3.10.jar&lt;BR /&gt;./jars/spring-core-5.3.12.jar&lt;BR /&gt;./jars/spring-core-5.3.13.jar&lt;BR /&gt;./jars/spring-core-5.3.4.jar&lt;BR /&gt;&lt;BR /&gt;Is CDP vulnerable to these vulnerabilities?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://tanzu.vmware.com/security/cve-2022-22970" target="_blank" rel="noopener"&gt;https://tanzu.vmware.com/security/cve-2022-22970&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://tanzu.vmware.com/security/cve-2022-22971" target="_blank" rel="noopener"&gt;https://tanzu.vmware.com/security/cve-2022-22971&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Oct 2022 14:51:33 GMT</pubDate>
    <dc:creator>loubershad</dc:creator>
    <dc:date>2022-10-26T14:51:33Z</dc:date>
    <item>
      <title>CVE-2022-22970 and CVE-2022-22971 spring-core vulnerabilities</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CVE-2022-22970-and-CVE-2022-22971-spring-core/m-p/356215#M237227</link>
      <description>&lt;P&gt;Our vulnerability scanning found these two vulnerabilities on our CDP Private Cloud 7.1.7-SP1,&amp;nbsp;CVE-2022-22970 and CVE-2022-22971.&amp;nbsp; There are several versions of spring-core in the parcel, none of which are the recommended version:&lt;BR /&gt;&lt;BR /&gt;./jars/spring-core-4.3.29.RELEASE.jar&lt;BR /&gt;./jars/spring-core-5.2.18.RELEASE.jar&lt;BR /&gt;./jars/spring-core-5.3.10.jar&lt;BR /&gt;./jars/spring-core-5.3.12.jar&lt;BR /&gt;./jars/spring-core-5.3.13.jar&lt;BR /&gt;./jars/spring-core-5.3.4.jar&lt;BR /&gt;&lt;BR /&gt;Is CDP vulnerable to these vulnerabilities?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://tanzu.vmware.com/security/cve-2022-22970" target="_blank" rel="noopener"&gt;https://tanzu.vmware.com/security/cve-2022-22970&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://tanzu.vmware.com/security/cve-2022-22971" target="_blank" rel="noopener"&gt;https://tanzu.vmware.com/security/cve-2022-22971&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 14:51:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CVE-2022-22970-and-CVE-2022-22971-spring-core/m-p/356215#M237227</guid>
      <dc:creator>loubershad</dc:creator>
      <dc:date>2022-10-26T14:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-22970 and CVE-2022-22971 spring-core vulnerabilities</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CVE-2022-22970-and-CVE-2022-22971-spring-core/m-p/356236#M237235</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/8264"&gt;@loubershad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current available GA versions of CDP does not have the fix included for the mentioned CVE (&lt;SPAN&gt;CVE-2022-22970 and CVE-2022-22971)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, it is currently planned and should be available with&amp;nbsp;upcoming release of CDP&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 17:09:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CVE-2022-22970-and-CVE-2022-22971-spring-core/m-p/356236#M237235</guid>
      <dc:creator>pajoshi</dc:creator>
      <dc:date>2022-10-26T17:09:36Z</dc:date>
    </item>
  </channel>
</rss>

