<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: security related problem file in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/security-related-problem-file/m-p/413647#M254177</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/84260"&gt;@jI-mi&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/86141"&gt;@haridjh&lt;/a&gt;&amp;nbsp;told, it will be good to know the CVE that you're seeing to confirm if this is solved or reported.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyways, there are some fixed Apache Shiro CVEs documented here:&amp;nbsp;&lt;/P&gt;&lt;P&gt;7.1.8 CHF2:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf2-pvcb-718.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf2-pvcb-718.html&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;CDPD-45726 - Upgrade Shiro to 1.10.0 due to CVE-2022-40664&lt;BR /&gt;CDPD-45727 - CDPD - Upgrade Shiro to 1.10.0 due to CVE-2022-40664&lt;/P&gt;&lt;P&gt;7.1.8 CHF18:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf18-pvcb-718.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf18-pvcb-718.html&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;CDPD-59365: CDPD - Upgrade Shiro to 1.12.0 due to CVE-2023-34478&lt;BR /&gt;CDPD-59364: Upgrade Shiro to 1.12.0 due to CVE-2023-34478&amp;nbsp;&lt;/P&gt;&lt;P&gt;7.1.8 CHF19: &lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf19-pvcb-718.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf19-pvcb-718.html&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;CDPD-65013: CDPD - Upgrade Apache Shiro to 1.13.0 due to CVE-2023-46750&lt;BR /&gt;CDPD-65012: Upgrade Apache Shiro to 1.13.0 due to CVE-2023-46750&lt;/P&gt;&lt;P&gt;7.1.9:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/runtime-release-notes/topics/fixed_common_vulnerabilities_exposures_719.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/runtime-release-notes/topics/fixed_common_vulnerabilities_exposures_719.html&lt;/A&gt;&lt;BR /&gt;CVE-2023-22602 - When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass.&lt;/P&gt;&lt;P&gt;7.1.9 SP1:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/runtime-release-notes/topics/rt-pvc-cve-719sp1.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/runtime-release-notes/topics/rt-pvc-cve-719sp1.html&lt;/A&gt;&lt;BR /&gt;CVE-2023-34478 Apache Shiro&lt;BR /&gt;CVE-2023-46749 Apache Shiro&lt;BR /&gt;CVE-2023-46750 Apache Shiro&lt;/P&gt;&lt;P&gt;7.1.3 SP3 CHF1:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.3.1/private-release-notes/topics/fixed-common-vulnerabilities-exposures-731_600.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.3.1/private-release-notes/topics/fixed-common-vulnerabilities-exposures-731_600.html&lt;/A&gt;&lt;BR /&gt;CVE-2023-46750 - Shiro Ehcache&lt;BR /&gt;CVE-2023-46749 - Shiro Ehcache&lt;BR /&gt;CVE-2023-34478 - Shiro Ehcache&lt;BR /&gt;CVE-2023-22602 - Shiro Ehcache&lt;BR /&gt;CVE-2022-40664 - Shiro Ehcache&lt;BR /&gt;CVE-2022-32532 - Shiro Ehcache&lt;BR /&gt;CVE-2021-41303 - Shiro Ehcache&lt;BR /&gt;CVE-2020-1957 - Shiro Ehcache&lt;BR /&gt;CVE-2020-17523 - Shiro Ehcache&lt;BR /&gt;CVE-2020-17510 - Shiro Ehcache&lt;BR /&gt;CVE-2020-13933 - Shiro Ehcache&lt;BR /&gt;CVE-2020-11989 - Shiro Ehcache&lt;BR /&gt;CVE-2019-12422 - Shiro Ehcache&lt;BR /&gt;CVE-2016-4437 - Shiro Ehcache&lt;BR /&gt;CVE-2010-3863 - Shiro Ehcache&lt;/P&gt;&lt;P&gt;Take a look on those CVE and see if the one you need to resolve is included there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found two that looks similar to what you mentioned:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2023-46749" target="_blank"&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-46749&lt;/A&gt;&amp;nbsp;solved in 7.1.9 SP1&lt;BR /&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2023-46750" target="_blank"&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-46750&lt;/A&gt;&amp;nbsp;solved in&amp;nbsp;7.1.8 CHF19&lt;/P&gt;</description>
    <pubDate>Wed, 04 Mar 2026 23:09:32 GMT</pubDate>
    <dc:creator>vafs</dc:creator>
    <dc:date>2026-03-04T23:09:32Z</dc:date>
    <item>
      <title>security related problem file</title>
      <link>https://community.cloudera.com/t5/Support-Questions/security-related-problem-file/m-p/413640#M254171</link>
      <description>&lt;P&gt;I am a Korean user. Recently, I received instructions to address the Apache Shiro security issue pointed out by the Korean Financial Supervisory Service. I am currently using CDH 7.1.8-1 and was instructed to update Shiro from the current version 1.11 to 1.13 or higher. As far as I know, it is being used in multiple places such as Knox and Kafka. Could you please let me know how to update it as soon as possible?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 04:20:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/security-related-problem-file/m-p/413640#M254171</guid>
      <dc:creator>jI-mi</dc:creator>
      <dc:date>2026-03-04T04:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: security related problem file</title>
      <link>https://community.cloudera.com/t5/Support-Questions/security-related-problem-file/m-p/413643#M254173</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/84260"&gt;@jI-mi&lt;/a&gt;&amp;nbsp;Could you please share the CVE or vulnerability details with the usage of Apache Shiro Version.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 14:28:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/security-related-problem-file/m-p/413643#M254173</guid>
      <dc:creator>haridjh</dc:creator>
      <dc:date>2026-03-04T14:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: security related problem file</title>
      <link>https://community.cloudera.com/t5/Support-Questions/security-related-problem-file/m-p/413647#M254177</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/84260"&gt;@jI-mi&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/86141"&gt;@haridjh&lt;/a&gt;&amp;nbsp;told, it will be good to know the CVE that you're seeing to confirm if this is solved or reported.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyways, there are some fixed Apache Shiro CVEs documented here:&amp;nbsp;&lt;/P&gt;&lt;P&gt;7.1.8 CHF2:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf2-pvcb-718.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf2-pvcb-718.html&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;CDPD-45726 - Upgrade Shiro to 1.10.0 due to CVE-2022-40664&lt;BR /&gt;CDPD-45727 - CDPD - Upgrade Shiro to 1.10.0 due to CVE-2022-40664&lt;/P&gt;&lt;P&gt;7.1.8 CHF18:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf18-pvcb-718.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf18-pvcb-718.html&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;CDPD-59365: CDPD - Upgrade Shiro to 1.12.0 due to CVE-2023-34478&lt;BR /&gt;CDPD-59364: Upgrade Shiro to 1.12.0 due to CVE-2023-34478&amp;nbsp;&lt;/P&gt;&lt;P&gt;7.1.8 CHF19: &lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf19-pvcb-718.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/runtime-release-notes/topics/chf19-pvcb-718.html&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;CDPD-65013: CDPD - Upgrade Apache Shiro to 1.13.0 due to CVE-2023-46750&lt;BR /&gt;CDPD-65012: Upgrade Apache Shiro to 1.13.0 due to CVE-2023-46750&lt;/P&gt;&lt;P&gt;7.1.9:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/runtime-release-notes/topics/fixed_common_vulnerabilities_exposures_719.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/runtime-release-notes/topics/fixed_common_vulnerabilities_exposures_719.html&lt;/A&gt;&lt;BR /&gt;CVE-2023-22602 - When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass.&lt;/P&gt;&lt;P&gt;7.1.9 SP1:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/runtime-release-notes/topics/rt-pvc-cve-719sp1.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/runtime-release-notes/topics/rt-pvc-cve-719sp1.html&lt;/A&gt;&lt;BR /&gt;CVE-2023-34478 Apache Shiro&lt;BR /&gt;CVE-2023-46749 Apache Shiro&lt;BR /&gt;CVE-2023-46750 Apache Shiro&lt;/P&gt;&lt;P&gt;7.1.3 SP3 CHF1:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.3.1/private-release-notes/topics/fixed-common-vulnerabilities-exposures-731_600.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.3.1/private-release-notes/topics/fixed-common-vulnerabilities-exposures-731_600.html&lt;/A&gt;&lt;BR /&gt;CVE-2023-46750 - Shiro Ehcache&lt;BR /&gt;CVE-2023-46749 - Shiro Ehcache&lt;BR /&gt;CVE-2023-34478 - Shiro Ehcache&lt;BR /&gt;CVE-2023-22602 - Shiro Ehcache&lt;BR /&gt;CVE-2022-40664 - Shiro Ehcache&lt;BR /&gt;CVE-2022-32532 - Shiro Ehcache&lt;BR /&gt;CVE-2021-41303 - Shiro Ehcache&lt;BR /&gt;CVE-2020-1957 - Shiro Ehcache&lt;BR /&gt;CVE-2020-17523 - Shiro Ehcache&lt;BR /&gt;CVE-2020-17510 - Shiro Ehcache&lt;BR /&gt;CVE-2020-13933 - Shiro Ehcache&lt;BR /&gt;CVE-2020-11989 - Shiro Ehcache&lt;BR /&gt;CVE-2019-12422 - Shiro Ehcache&lt;BR /&gt;CVE-2016-4437 - Shiro Ehcache&lt;BR /&gt;CVE-2010-3863 - Shiro Ehcache&lt;/P&gt;&lt;P&gt;Take a look on those CVE and see if the one you need to resolve is included there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found two that looks similar to what you mentioned:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2023-46749" target="_blank"&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-46749&lt;/A&gt;&amp;nbsp;solved in 7.1.9 SP1&lt;BR /&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2023-46750" target="_blank"&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-46750&lt;/A&gt;&amp;nbsp;solved in&amp;nbsp;7.1.8 CHF19&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 23:09:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/security-related-problem-file/m-p/413647#M254177</guid>
      <dc:creator>vafs</dc:creator>
      <dc:date>2026-03-04T23:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: security related problem file</title>
      <link>https://community.cloudera.com/t5/Support-Questions/security-related-problem-file/m-p/413694#M254193</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/84260"&gt;@jI-mi&lt;/a&gt;&amp;nbsp;Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;nbsp; Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 02:41:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/security-related-problem-file/m-p/413694#M254193</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2026-03-11T02:41:06Z</dc:date>
    </item>
  </channel>
</rss>

