<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question CVE-2022-42889 Apache Commons Text Text4Shell in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/CVE-2022-42889-Apache-Commons-Text-Text4Shell/m-p/358906#M237973</link>
    <description>&lt;P&gt;It looks like CDH 7.1.7 SP1 is vulnerable to&amp;nbsp;CVE-2022-42889.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the announcement from Apache which indicates the mitigation is to "Upgrade to Apache Commons Text 1.10.0".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om" target="_blank" rel="noopener"&gt;https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There was another community thread about Text4Shell in NiFi, but CVE-2022-42889 is NOT just a NiFi issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CDH 7.1.7 SP1 (even p1057) includes the vulnerable common-jars 1.6/1.7 and 1.9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/jars/commons-text-1.6.jar&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/jars/commons-text-1.7.jar&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/jars/commons-text-1.9.jar&lt;BR /&gt;...&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/lib/solr/server/solr-webapp/webapp/WEB-INF/lib/commons-text-1.6.jar&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/lib/streams_messaging_manager/libs/commons-text-1.9.jar&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/lib/streams_replication_manager/lib/commons-text-1.9.jar#&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a time frame for 1.10 (or better)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2022 21:18:03 GMT</pubDate>
    <dc:creator>jgabrey-1216863216</dc:creator>
    <dc:date>2022-12-05T21:18:03Z</dc:date>
    <item>
      <title>CVE-2022-42889 Apache Commons Text Text4Shell</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CVE-2022-42889-Apache-Commons-Text-Text4Shell/m-p/358906#M237973</link>
      <description>&lt;P&gt;It looks like CDH 7.1.7 SP1 is vulnerable to&amp;nbsp;CVE-2022-42889.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the announcement from Apache which indicates the mitigation is to "Upgrade to Apache Commons Text 1.10.0".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om" target="_blank" rel="noopener"&gt;https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There was another community thread about Text4Shell in NiFi, but CVE-2022-42889 is NOT just a NiFi issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CDH 7.1.7 SP1 (even p1057) includes the vulnerable common-jars 1.6/1.7 and 1.9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/jars/commons-text-1.6.jar&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/jars/commons-text-1.7.jar&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/jars/commons-text-1.9.jar&lt;BR /&gt;...&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/lib/solr/server/solr-webapp/webapp/WEB-INF/lib/commons-text-1.6.jar&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/lib/streams_messaging_manager/libs/commons-text-1.9.jar&lt;BR /&gt;/opt/cloudera/parcels/CDH-7.1.7-1.cdh7.1.7.p1057.32088321/lib/streams_replication_manager/lib/commons-text-1.9.jar#&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a time frame for 1.10 (or better)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 21:18:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CVE-2022-42889-Apache-Commons-Text-Text4Shell/m-p/358906#M237973</guid>
      <dc:creator>jgabrey-1216863216</dc:creator>
      <dc:date>2022-12-05T21:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-42889 Apache Commons Text Text4Shell</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CVE-2022-42889-Apache-Commons-Text-Text4Shell/m-p/359097#M238018</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/1115"&gt;@jgabrey-1216863216&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This has been fixed in CDP 7.1.7 SP1 CHF20 (&lt;SPAN&gt;p1063). You can refer the below doc :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.7/runtime-release-notes/topics/chf-pvcb-sp1-overview.html#ariaid-title2" target="_blank"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.7/runtime-release-notes/topics/chf-pvcb-sp1-overview.html#ariaid-title2&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 06:31:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CVE-2022-42889-Apache-Commons-Text-Text4Shell/m-p/359097#M238018</guid>
      <dc:creator>rki_</dc:creator>
      <dc:date>2022-12-08T06:31:45Z</dc:date>
    </item>
  </channel>
</rss>

