Support Questions

Find answers, ask questions, and share your expertise
Announcements
Celebrating as our community reaches 100,000 members! Thank you!

CDP minor upgrade to close vulnerability

avatar
Expert Contributor

Hi Experts,

 

We are on 7.1.6 CDP version and exposed to CVE-2022-25168. 

 

Versions affected: 2.0.0 to 2.10.1, 3.0.0-alpha to 3.2.3, 3.3.0 to 3.3.2

 

To address this vulnerability, we are planning to upgrade to CDP 7.1.7 as I got this information from one of the posts in the cloudera community.

 

My question is does anyone did this upgrade before from 7.1.6 to 7.1.7 to eliminate this CVE. If yes, then how easy is it do we need to make changes in the code level also or we can do the upgrade from the GUI by just downloading, distributing and activating the new version.  

 

Please help with your suggestion and if possible, please share the documentation for this upgrade.

 

Thanks

 

1 ACCEPTED SOLUTION

avatar
Expert Contributor

Since we are using CDW Cloudera data warehouse, upon doing some research I can say there no change required on code level as we are using hive on Tez and it is going to be a not a major upgrade as we do from CDH to CDP.

Hence accepting this as a solution to my query after thorough research.

View solution in original post

2 REPLIES 2

avatar
Expert Contributor

Since we are using CDW Cloudera data warehouse, upon doing some research I can say there no change required on code level as we are using hive on Tez and it is going to be a not a major upgrade as we do from CDH to CDP.

Hence accepting this as a solution to my query after thorough research.

avatar
Community Manager

Thank you for posting your findings @HanzalaShaikh 


Cy Jervis, Manager, Community Program
Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.