Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Spark & log4j security #163

Open
dolsysmith opened this issue Dec 14, 2021 · 0 comments
Open

Spark & log4j security #163

dolsysmith opened this issue Dec 14, 2021 · 0 comments

Comments

@dolsysmith
Copy link
Contributor

Spark uses log4j, but I don't think the CVE-2021-44228 vulnerability exposes our application, since we don't expose the Spark UI, and since the data pipeline flows only one way (into the rest of the application from Spark); the only way to interact with Spark is from the command line. But best practice would be either to apply the log4j patch or add the command-line parameter to the Dockerfile to disable the problematic log4j property at startup.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant