<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Removing Spark1.6 in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/90983#M84727</link>
    <description>&lt;P&gt;Hi Sara, I run vulnerability scans and our scanner picking up Spark 1.6 banner from the following path- for&lt;/P&gt;&lt;P&gt;CVE-2018-8024 vulnerability, you did mention this vulnerability doesn't affect SPark 1.6 but didn't give detail reasons. This is where Qualys picksup the banner-&lt;/P&gt;&lt;P&gt;/opt/cloudera/parcels/CDH-5.15.1-1.cdh5.15.1.p0.4/lib/spark/conf/spark-env.sh: line 75: /usr/appl/cloudera/java/jdk1.8.0_162: is a directory&lt;/P&gt;&lt;P&gt;Welcome to&lt;BR /&gt;____&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; __&lt;BR /&gt;/ __/__&amp;nbsp; ___ _____/ /__&lt;BR /&gt;_\ \/ _ \/ _ `/ __/&amp;nbsp; '_/&lt;BR /&gt;/___/ .__/\_,_/_/ /_/\_\&amp;nbsp;&amp;nbsp; version 1.6.0&lt;BR /&gt;/_/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also we have 2 versions of SPARK running- do you really need version 1.6 to run v 2.3.0&lt;/P&gt;&lt;P&gt;Can you please help, advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 May 2019 18:24:18 GMT</pubDate>
    <dc:creator>PatliGalli</dc:creator>
    <dc:date>2019-05-28T18:24:18Z</dc:date>
    <item>
      <title>Removing Spark1.6</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/81996#M84723</link>
      <description>&lt;P&gt;We're using CDH 5.12.1 currently, which ships with Spark1.6. We have deployed Spark2.3 on the cluster, which is the distribution that we're actively using, and is working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, this does mean that we've got Spark1.6 binaries on our servers. Our security scans have picked these up as a vulnerability and we'd like to go ahead and remove them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering if anyone has attempted something like this before? If so, do they have any advice regarding it? I was simply going to have a look at what Spark1.6 files there are, then write a script that looped through our cluster and removed those files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone has a more "official" way of doing things, that would be preferable. I'm more than aware that my proposal wouldn't exactly be supported.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a follow up, have the Spark1.6 binaries been removed from more recent CDH versions?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 13:52:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/81996#M84723</guid>
      <dc:creator>JTRexp</dc:creator>
      <dc:date>2022-09-16T13:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Spark1.6</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/82622#M84724</link>
      <description>- CVE-2018-8024: doesn’t affect Spark1.6.
- CVE-2018-1334: fixed in CDH5.14.4, CDH5.15.1, CDH5.12.3 and CDH5.16.0. You can upgrade to one of these versions to resolve the issue.</description>
      <pubDate>Tue, 20 Nov 2018 12:37:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/82622#M84724</guid>
      <dc:creator>SaraNab</dc:creator>
      <dc:date>2018-11-20T12:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Spark1.6</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/90249#M84725</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;CVE-2018-1334 is fixed in CDH 5.15.1 and higher version.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 09:51:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/90249#M84725</guid>
      <dc:creator>Yuexin Zhang</dc:creator>
      <dc:date>2019-05-10T09:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Spark1.6</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/90323#M84726</link>
      <description>&lt;P&gt;To be more acturate, technically,&amp;nbsp;&lt;SPAN&gt;CVE-2018-1334 is fixed in CDH 5.14.4. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But there's a new issue been found with similar&amp;nbsp;&lt;/SPAN&gt;privilege escalation vulnerability, which is CVE-2018-11760. We fixed&amp;nbsp;CVE-2018-11760 in CDH 5.15.1. So with CDH 5.15.1, you won't be affected by these two&lt;SPAN&gt;&amp;nbsp;similar&amp;nbsp;&lt;/SPAN&gt;privilege escalation vulnerabilities.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 11:29:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/90323#M84726</guid>
      <dc:creator>Yuexin Zhang</dc:creator>
      <dc:date>2019-05-13T11:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Spark1.6</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/90983#M84727</link>
      <description>&lt;P&gt;Hi Sara, I run vulnerability scans and our scanner picking up Spark 1.6 banner from the following path- for&lt;/P&gt;&lt;P&gt;CVE-2018-8024 vulnerability, you did mention this vulnerability doesn't affect SPark 1.6 but didn't give detail reasons. This is where Qualys picksup the banner-&lt;/P&gt;&lt;P&gt;/opt/cloudera/parcels/CDH-5.15.1-1.cdh5.15.1.p0.4/lib/spark/conf/spark-env.sh: line 75: /usr/appl/cloudera/java/jdk1.8.0_162: is a directory&lt;/P&gt;&lt;P&gt;Welcome to&lt;BR /&gt;____&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; __&lt;BR /&gt;/ __/__&amp;nbsp; ___ _____/ /__&lt;BR /&gt;_\ \/ _ \/ _ `/ __/&amp;nbsp; '_/&lt;BR /&gt;/___/ .__/\_,_/_/ /_/\_\&amp;nbsp;&amp;nbsp; version 1.6.0&lt;BR /&gt;/_/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also we have 2 versions of SPARK running- do you really need version 1.6 to run v 2.3.0&lt;/P&gt;&lt;P&gt;Can you please help, advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 18:24:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Removing-Spark1-6/m-p/90983#M84727</guid>
      <dc:creator>PatliGalli</dc:creator>
      <dc:date>2019-05-28T18:24:18Z</dc:date>
    </item>
  </channel>
</rss>

