Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created on 11-16-2022 08:08 AM - edited 11-16-2022 11:03 AM
I believe below mentioned CVEs are either addressed or fixed through patching in CDH 6.3.4 -
But apart from above vulnerabilities, there are few more vulnerabilities of critical, high and moderate severity in Log4j1 and Log4j2 which are -
Log4j1 - https://logging.apache.org/log4j/1.2/index.html
Log4j2 - https://logging.apache.org/log4j/2.x/security.html
[EDITED] - Is CDH 6.3.4 exposed to these, above mentioned, other CVEs? And if so -
Are there any patches released for these vulnerabilities as well for CDH 6.3.4?
Created 11-16-2022 08:24 AM
I'm curious as to exactly how you have determined that, because you have identified that there are previously identified vulnerabilities of critical, high and moderate severity in Log4j1 and Log4j2, that CDH 6.3.4 is exposed to those same vulnerabilities?
Created on 11-16-2022 10:07 AM - edited 11-16-2022 11:02 AM
@ask_bill_brooks Thanks for the quick response.
I am not yet sure that CDH 6.3.4 is exposed to those Log4J1 and Log4J2 vulnerabilities or not.
Maybe I should update my question that "...if CDH 6.3.4 is affected by those other CVEs then are there any fixes/patches or not?"
Thank you for pointing that out.