<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Critical vulnerability CVE-2014-0114 found in CDP 7.1.7 SP1 commons-fileupload-1.3.3.jar in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Critical-vulnerability-CVE-2014-0114-found-in-CDP-7-1-7-SP1/m-p/387500#M246335</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/110403"&gt;@EY&lt;/a&gt;&amp;nbsp;Thanks for bringing this to our community.&lt;/P&gt;&lt;P&gt;The CVE-ID does not seem to be the appropriate one for the Apache struts vulnerability shared. Help us with the following to understand this better:&lt;/P&gt;&lt;P&gt;1. What is the Security tool used and the version of it?&lt;BR /&gt;2. Share the flagged CVE from the security team.&lt;BR /&gt;3. Full CDP version&lt;/P&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0014" target="_blank"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0014&lt;/A&gt;&lt;/P&gt;&lt;P&gt;V&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2024 14:32:18 GMT</pubDate>
    <dc:creator>vaishaakb</dc:creator>
    <dc:date>2024-05-02T14:32:18Z</dc:date>
    <item>
      <title>Critical vulnerability CVE-2014-0114 found in CDP 7.1.7 SP1 commons-fileupload-1.3.3.jar</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Critical-vulnerability-CVE-2014-0114-found-in-CDP-7-1-7-SP1/m-p/387498#M246333</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We got critical vulnerability CVE-2014-0014 found in CDP 7.1.7 SP1 commons-fileupload-1.3.3.jar, could you please check and confirm if Apache Struts is used in the Cloudera 7.1.7 SP1? Thanks.&lt;/P&gt;&lt;P&gt;Path:&lt;/P&gt;&lt;P&gt;./jars/commons-fileupload-1.3.3.jar&lt;BR /&gt;./lib/atlas/extractors/lib/azure-adls/commons-fileupload-1.3.3.jar&lt;BR /&gt;./lib/atlas/extractors/lib/aws-s3/commons-fileupload-1.3.3.jar&lt;BR /&gt;./lib/atlas/server/webapp/atlas/WEB-INF/lib/commons-fileupload-1.3.3.jar&lt;BR /&gt;./lib/search/lib/commons-fileupload-1.3.3.jar&lt;BR /&gt;./lib/solr/server/solr-webapp/webapp/WEB-INF/lib/commons-fileupload-1.3.3.jar&lt;BR /&gt;./lib/hbase-solr/lib/commons-fileupload-1.3.3.jar&lt;BR /&gt;./lib/oozie/oozie-sharelib-yarn/lib/spark/commons-fileupload-1.3.3.jar&lt;BR /&gt;./lib/search/lib/search-crunch/commons-fileupload-1.3.3.jar&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 06:31:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Critical-vulnerability-CVE-2014-0114-found-in-CDP-7-1-7-SP1/m-p/387498#M246333</guid>
      <dc:creator>EY</dc:creator>
      <dc:date>2026-04-21T06:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Critical vulnerability CVE-2014-0114 found in CDP 7.1.7 SP1 commons-fileupload-1.3.3.jar</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Critical-vulnerability-CVE-2014-0114-found-in-CDP-7-1-7-SP1/m-p/387500#M246335</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/110403"&gt;@EY&lt;/a&gt;&amp;nbsp;Thanks for bringing this to our community.&lt;/P&gt;&lt;P&gt;The CVE-ID does not seem to be the appropriate one for the Apache struts vulnerability shared. Help us with the following to understand this better:&lt;/P&gt;&lt;P&gt;1. What is the Security tool used and the version of it?&lt;BR /&gt;2. Share the flagged CVE from the security team.&lt;BR /&gt;3. Full CDP version&lt;/P&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0014" target="_blank"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0014&lt;/A&gt;&lt;/P&gt;&lt;P&gt;V&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 14:32:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Critical-vulnerability-CVE-2014-0114-found-in-CDP-7-1-7-SP1/m-p/387500#M246335</guid>
      <dc:creator>vaishaakb</dc:creator>
      <dc:date>2024-05-02T14:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: Critical vulnerability CVE-2014-0114 found in CDP 7.1.7 SP1 commons-fileupload-1.3.3.jar</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Critical-vulnerability-CVE-2014-0114-found-in-CDP-7-1-7-SP1/m-p/387505#M246336</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29989"&gt;@vaishaakb&lt;/a&gt;&amp;nbsp;, thanks for your reply.&lt;/P&gt;&lt;P&gt;1. The Security tool is ITAG Struts Tanium but i am not sure of the version&lt;/P&gt;&lt;P&gt;2. Flagged CVE is&amp;nbsp;&lt;SPAN&gt;CVE-2014-0014, and we doubt it's false positive reported since we checked for this CVE is for&amp;nbsp;commons-beanutils.jar in Apache Struts. But security team requested us to confirm with Cloudera team on whether Apache Struts is used in the Cloudera Data Platform (CDP) 7.1.7 SP1 and&amp;nbsp;CDP was vulnerable to CVE-2014-0114.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3.&amp;nbsp;Full CDP version is : 7.1.7-1.cdh7.1.7.p1050.30900109&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you please advise on this. Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 15:12:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Critical-vulnerability-CVE-2014-0114-found-in-CDP-7-1-7-SP1/m-p/387505#M246336</guid>
      <dc:creator>EY</dc:creator>
      <dc:date>2024-05-02T15:12:35Z</dc:date>
    </item>
  </channel>
</rss>

