<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2021-44228 in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33358#M24366</link>
    <description>&lt;P&gt;on the databricks docs you get an overview of the installed version by databricks-version:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/release-notes/runtime/releases.html" target="test_blank"&gt;https://docs.databricks.com/release-notes/runtime/releases.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Select the release you use and then search for 'log4j'.&lt;/P&gt;&lt;P&gt;Of course that is no guarantee, because you can submit your own fat jars with another log4j version included.&lt;/P&gt;&lt;P&gt;If you do not do that, that is not an issue ofc.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Dec 2021 08:50:32 GMT</pubDate>
    <dc:creator>-werners-</dc:creator>
    <dc:date>2021-12-13T08:50:32Z</dc:date>
    <item>
      <title>CVE-2021-44228</title>
      <link>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33354#M24362</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any affect of CVE-2021-44228 problem on Databricks platform?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any action that needs to be done by Databricks customer related to CVE-2021-44228?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2021 19:45:00 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33354#M24362</guid>
      <dc:creator>herry</dc:creator>
      <dc:date>2021-12-11T19:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228</title>
      <link>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33355#M24363</link>
      <description>&lt;P&gt;Databricks is still on log4j 1. That alert is related to log4j 2.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2021 19:55:41 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33355#M24363</guid>
      <dc:creator>Hubert-Dudek</dc:creator>
      <dc:date>2021-12-11T19:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228</title>
      <link>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33356#M24364</link>
      <description>&lt;P&gt;It depends.&lt;/P&gt;&lt;P&gt;The vulnerability in question is &lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228" alt="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228" target="_blank"&gt;CVE-2021-44228&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Log4j 2.0-beta9 to 2.14.1 are vulnerable. With version 2.15.0 the issue is resolved.&lt;/P&gt;&lt;P&gt;So it depends on the version of Log4j you are running.&lt;/P&gt;&lt;P&gt;You can set 'log4j2.formatMsgNoLookups' to 'true' by addubg ‐Dlog4j2.formatMsgNoLookups=True” to the cluster startup params.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not know the log4j versions per databricks version.&lt;/P&gt;&lt;P&gt;Maybe someone from databricks can tell us which versions are impacted.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 08:08:01 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33356#M24364</guid>
      <dc:creator>-werners-</dc:creator>
      <dc:date>2021-12-13T08:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228</title>
      <link>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33357#M24365</link>
      <description>&lt;P&gt;How can I know which version I have?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 08:39:28 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33357#M24365</guid>
      <dc:creator>Kencorp</dc:creator>
      <dc:date>2021-12-13T08:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228</title>
      <link>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33358#M24366</link>
      <description>&lt;P&gt;on the databricks docs you get an overview of the installed version by databricks-version:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/release-notes/runtime/releases.html" target="test_blank"&gt;https://docs.databricks.com/release-notes/runtime/releases.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Select the release you use and then search for 'log4j'.&lt;/P&gt;&lt;P&gt;Of course that is no guarantee, because you can submit your own fat jars with another log4j version included.&lt;/P&gt;&lt;P&gt;If you do not do that, that is not an issue ofc.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 08:50:32 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33358#M24366</guid>
      <dc:creator>-werners-</dc:creator>
      <dc:date>2021-12-13T08:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228</title>
      <link>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33359#M24367</link>
      <description>&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 09:02:38 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33359#M24367</guid>
      <dc:creator>Kencorp</dc:creator>
      <dc:date>2021-12-13T09:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228</title>
      <link>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33360#M24368</link>
      <description>&lt;P&gt;On most databricks distributions log4j version is 1.2.17&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 11:48:38 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cve-2021-44228/m-p/33360#M24368</guid>
      <dc:creator>Hubert-Dudek</dc:creator>
      <dc:date>2021-12-13T11:48:38Z</dc:date>
    </item>
  </channel>
</rss>

