Created on 11-16-2022 08:08 AM - edited 11-16-2022 11:03 AM
I believe below mentioned CVEs are either addressed or fixed through patching in CDH 6.3.4 -
But apart from above vulnerabilities, there are few more vulnerabilities of critical, high and moderate severity in Log4j1 and Log4j2 which are -
Log4j1 - https://logging.apache.org/log4j/1.2/index.html
Log4j2 - https://logging.apache.org/log4j/2.x/security.html
[EDITED] - Is CDH 6.3.4 exposed to these, above mentioned, other CVEs? And if so -
Are there any patches released for these vulnerabilities as well for CDH 6.3.4?
Created 11-16-2022 08:24 AM
I'm curious as to exactly how you have determined that, because you have identified that there are previously identified vulnerabilities of critical, high and moderate severity in Log4j1 and Log4j2, that CDH 6.3.4 is exposed to those same vulnerabilities?
Created on 11-16-2022 10:07 AM - edited 11-16-2022 11:02 AM
@ask_bill_brooks Thanks for the quick response.
I am not yet sure that CDH 6.3.4 is exposed to those Log4J1 and Log4J2 vulnerabilities or not.
Maybe I should update my question that "...if CDH 6.3.4 is affected by those other CVEs then are there any fixes/patches or not?"
Thank you for pointing that out.