Support Questions

Find answers, ask questions, and share your expertise
Announcements
Celebrating as our community reaches 100,000 members! Thank you!

Cloudera 5.16.2: Tomcat upgrade

avatar
Explorer

Hello,

 

After running a security tool on our cluster, a report found the tomcat version as outdated and vulnerable to certain threats. We have tried to find ways to upgrade Tomcat on our cluster but are not having any success with it.

 

I realize this is similar to a post https://community.cloudera.com/t5/Support-Questions/Apache-tomcat-compatibility/m-p/159988 which concerns HDP but there are no responses on that post either.

 

Does anyone have some experience with this? If so, I would be grateful for some pointers.

Thanks.

 

Regards,

CaptainJay

1 ACCEPTED SOLUTION

avatar
Master Guru

@CaptainJa  The version of Tomcat used in CDH 5.16.2 should not have any vulnerabilities. Could you share the CVE that is reported CDH is vulnerable to?

 

Per the notice [1] independent upgrade of Tomcat is not supported and we are moving towards newer versions in CDH6 => Cloudera Enterprise 6 has replaced Tomcat 6 with Jetty 9 and is not susceptible to Tomcat security issues.

 

LINKS: [1] https://community.cloudera.com/t5/Customer/CDH-5-support-for-Tomcat-6/ta-p/73655


Cheers!
Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.

View solution in original post

3 REPLIES 3

avatar
Super Collaborator

Hi @CaptainJa 

 

Are you able to upgrade your environment to CDH 6? In CDH 6 Tomcat is replaced by Jetty. Please take a look at this post:

 

https://blog.cloudera.com/third-party-libraries-in-c6/

 

Regards,

Steve

avatar
Explorer

Hello @StevenOD,

 

Thanks for the reply. We have considered this but at the moment, the client requirements limits our usage to 5.16.x

avatar
Master Guru

@CaptainJa  The version of Tomcat used in CDH 5.16.2 should not have any vulnerabilities. Could you share the CVE that is reported CDH is vulnerable to?

 

Per the notice [1] independent upgrade of Tomcat is not supported and we are moving towards newer versions in CDH6 => Cloudera Enterprise 6 has replaced Tomcat 6 with Jetty 9 and is not susceptible to Tomcat security issues.

 

LINKS: [1] https://community.cloudera.com/t5/Customer/CDH-5-support-for-Tomcat-6/ta-p/73655


Cheers!
Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.