<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: What all vulnerabilities related to Log4j1 and Log4j2 are fixed/addressed in CDH 6.3.4? in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/What-all-vulnerabilities-related-to-Log4j1-and-Log4j2-are/m-p/357796#M237668</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/101861"&gt;@YogeshKumar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm curious as to exactly how you have determined that, because you have identified that there are previously identified vulnerabilities of critical, high and moderate severity in Log4j1 and Log4j2, that CDH 6.3.4 is exposed to those same vulnerabilities?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2022 16:24:06 GMT</pubDate>
    <dc:creator>ask_bill_brooks</dc:creator>
    <dc:date>2022-11-16T16:24:06Z</dc:date>
    <item>
      <title>What all vulnerabilities related to Log4j1 and Log4j2 are fixed/addressed in CDH 6.3.4?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/What-all-vulnerabilities-related-to-Log4j1-and-Log4j2-are/m-p/357794#M237667</link>
      <description>&lt;P&gt;I believe below mentioned CVEs are either addressed or fixed through patching in CDH 6.3.4 -&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A class="fui-Link ___m14voj0 f3rmtva f1ern45e f1deefiw f1n71otn f1q5o8ev f1h8hb77 f1vxd6vx f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1hu3pq6 f11qmguv f19f4twv f1tyq0we f1g0x7ka fhxju0i f1qch9an f1cnd47f fqv5qza f1vmzxwi f1o700av f13mvf36 f9n3di6 f1ids18y fygtlnl f1deo86v f12x56k7 f1iescvh ftqa4ok f50u1b5 fs3pq8b f1hghxdh f1tymzes f1x7u7e9 f1cmlufx f10aw75t fsle3fq" title="https://www.cvedetails.com/cve/CVE-2021-4104/" href="https://www.cvedetails.com/cve/CVE-2021-4104/" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;CVE-2021-4104&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;(Log4j1) - as per &lt;A href="https://community.cloudera.com/t5/Support-Announcements/Cloudera-response-to-CVE-2021-4104/ba-p/332287" target="_self"&gt;this&lt;/A&gt; article, CDH user doesn't need to do anything to fix this vulnerability.&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228" target="_self"&gt;CVE-2021-44228&lt;/A&gt;&amp;nbsp;(Log4j2) -&amp;nbsp; as per this article, patches are available for this vulnerability for CDH 6.3.4.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;But apart from above vulnerabilities, there are few more vulnerabilities of critical, high and moderate &lt;SPAN&gt;severity&lt;/SPAN&gt; in Log4j1 and Log4j2 which are -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log4j1 -&amp;nbsp;&lt;A href="https://logging.apache.org/log4j/1.2/index.html" target="_blank" rel="noopener"&gt;https://logging.apache.org/log4j/1.2/index.html&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://www.cvedetails.com/cve/CVE-2019-17571/" target="_blank" rel="noopener"&gt;CVE-2019-17571&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;is a high severity issue targeting the SocketServer.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.cvedetails.com/cve/CVE-2022-23302/" target="_blank" rel="noopener"&gt;CVE-2022-23302&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;is a high severity deserialization vulnerability in JMSSink.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.cvedetails.com/cve/CVE-2022-23305/" target="_blank" rel="noopener"&gt;CVE-2022-23305&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;is a high serverity SQL injection flaw in JDBCAppender that allows the data being logged to modify the behavior of the component.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://www.cvedetails.com/cve/CVE-2022-23307/" target="_blank" rel="noopener"&gt;CVE-2022-23307&lt;/A&gt;&amp;nbsp;is a critical severity against the chainsaw component in Log4j 1.x.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Log4j2 -&amp;nbsp;&lt;A href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="noopener"&gt;https://logging.apache.org/log4j/2.x/security.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A class="fui-Link ___m14voj0 f3rmtva f1ern45e f1deefiw f1n71otn f1q5o8ev f1h8hb77 f1vxd6vx f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1hu3pq6 f11qmguv f19f4twv f1tyq0we f1g0x7ka fhxju0i f1qch9an f1cnd47f fqv5qza f1vmzxwi f1o700av f13mvf36 f9n3di6 f1ids18y fygtlnl f1deo86v f12x56k7 f1iescvh ftqa4ok f50u1b5 fs3pq8b f1hghxdh f1tymzes f1x7u7e9 f1cmlufx f10aw75t fsle3fq" title="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;CVE-2021-45046&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;(critical severity) - Apache Log4j2 Thread Context Lookup Pattern vulnerable to remote code execution in certain non-default configurations.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A class="externalLink" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105" target="_blank" rel="noopener"&gt;CVE-2021-45105&lt;/A&gt;&amp;nbsp;(moderate severity) - Apache Log4j2 does not always protect from infinite recursion in lookup evaluation.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;[&lt;STRONG&gt;EDITED&lt;/STRONG&gt;] - Is CDH 6.3.4 exposed to these, above mentioned, other CVEs? And if so -&lt;/P&gt;&lt;P&gt;Are there any patches released for these vulnerabilities as well&amp;nbsp;for CDH 6.3.4?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 19:03:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/What-all-vulnerabilities-related-to-Log4j1-and-Log4j2-are/m-p/357794#M237667</guid>
      <dc:creator>YogeshKumar</dc:creator>
      <dc:date>2022-11-16T19:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: What all vulnerabilities related to Log4j1 and Log4j2 are fixed/addressed in CDH 6.3.4?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/What-all-vulnerabilities-related-to-Log4j1-and-Log4j2-are/m-p/357796#M237668</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/101861"&gt;@YogeshKumar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm curious as to exactly how you have determined that, because you have identified that there are previously identified vulnerabilities of critical, high and moderate severity in Log4j1 and Log4j2, that CDH 6.3.4 is exposed to those same vulnerabilities?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 16:24:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/What-all-vulnerabilities-related-to-Log4j1-and-Log4j2-are/m-p/357796#M237668</guid>
      <dc:creator>ask_bill_brooks</dc:creator>
      <dc:date>2022-11-16T16:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: What all vulnerabilities related to Log4j1 and Log4j2 are fixed/addressed in CDH 6.3.4?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/What-all-vulnerabilities-related-to-Log4j1-and-Log4j2-are/m-p/357806#M237671</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35418"&gt;@ask_bill_brooks&lt;/a&gt;&amp;nbsp;Thanks for the quick response.&lt;/P&gt;&lt;P&gt;I am not yet sure that CDH 6.3.4 is exposed to those Log4J1 and Log4J2 vulnerabilities or not.&lt;/P&gt;&lt;P&gt;Maybe I should update my question that "...if CDH 6.3.4 is affected by those other CVEs then are there any fixes/patches or not?"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for pointing that out.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 19:02:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/What-all-vulnerabilities-related-to-Log4j1-and-Log4j2-are/m-p/357806#M237671</guid>
      <dc:creator>YogeshKumar</dc:creator>
      <dc:date>2022-11-16T19:02:45Z</dc:date>
    </item>
  </channel>
</rss>

