Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Community Announcements

Find the latest community announcements
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!

Cloudera response to CVE-2021-4104

avatar
Community Manager

Cloudera is aware of CVE-2021-4104, which affects the Apache Log4j 1.x JMSAppender. This flaw only affects software that is explicitly configured to use the JMSAppender, which is not the default, or when the attacker has write access to the Log4j configuration for adding JMSAppender. Cloudera does not use JMSAppender in its products and it is not used by default in log4j properties. Cloudera customers do not need to take any action to address CVE-2021-4104. If you have further questions, please contact Cloudera Support through our My Cloudera Support portal.

 

Because Cloudera Manager and Ambari allow authenticated users with privileged access to modify cluster configuration to insert custom logging configuration, customers are advised to review the logging configuration for their clusters to ensure that they do not contain references to the JMSAppender. To find these settings, look for the following based on the cluster management tool in use:

  • Cloudera Manager: "{SERVICE_NAME} Logging Advanced Configuration Snippet (Safety Valve)"
  • Ambari: “Advanced{SERVICE_NAME}-log4j”
0 REPLIES 0