All Products
Search
Document Center

E-MapReduce:Security bulletin | Apache Log4j2 remote code execution vulnerability

Last Updated:Aug 20, 2026

Alibaba Cloud recently discovered a remote code execution (RCE) vulnerability in the Apache Log4j2 component and disclosed it to the Apache Software Foundation. This topic describes the impact of the vulnerability and the corresponding remediation plan.

Impact

In E-MapReduce (EMR), the affected components include Hive, Presto, Impala, Druid, Flink, Solr, Ranger, Storm, Oozie, Spark, and Zeppelin. Spark and Zeppelin are affected because they depend on the Hive component.

Remediation plan

You must replace the vulnerable Log4j2 JAR files in your EMR cluster with version 2.17.2 and modify the Hive and Spark Log4j configuration to disable the JNDI Lookup feature by setting log4j2.formatMsgNoLookups=true. For detailed instructions, see Remediation procedure.

This remediation plan has the following characteristics:

  • It applies to EMR-3.38.2 and earlier, EMR-5.4.2 and earlier, and EMR 4.x versions. The vulnerability is fixed in EMR-3.38.3 and later and EMR-5.4.3 and later. No action is required for these versions.

  • You must restart the corresponding components after applying this plan.

  • The remediation script does not impact your online services. However, because the fix only takes effect after the components are restarted, we recommend that you perform this procedure during off-peak hours.

Remediation procedure

EMR clusters

  1. Click patches-log4j.tar.gz to download the patch package.

  2. Log on to the master node of the EMR cluster, and place the patch package downloaded in Step 1 in the HOME directory of the emr-user or hadoop user.

  3. Decompress the patch package and run the following commands as the emr-user or hadoop user.

    • For DataLake, Dataflow, OLAP, DataServing, and custom scenario clusters:

      su emr-user
      tar zxf patches-log4j.tar.gz
    • For other clusters:

      su hadoop
      tar zxf patches-log4j.tar.gz
  4. Edit the hosts file in the patch package to add the hostnames of all nodes in the cluster, such as emr-header-1 or emr-worker-1. Add one hostname per line.

    cd patches
    vim hosts

    The following is an example of the hosts file content:

    emr-header-1
    emr-worker-1
    emr-worker-2
    Important

    For clusters that run EMR 3.41 or later in the EMR 3.x series, or EMR 5.7.0 or later in the EMR 5.x series, the hostname format has changed. The following is an example of the hosts file content:

    core-1-1
    core-1-2
    task-1-1
    task-1-2
  5. Run the fix.sh script to apply the fix.

    ./fix.sh

    After the script runs, it returns the following message:

    ### NOTICE: YOU CAN RESTORE THIS PATCH BY RUN RESTORE SCRIPT ABOVE
    $> sh ./restore.sh 20211213001755
    ### DONE

    To rollback the fix, run the following command:

    ./restore.sh 20211213001755
    Note

    For running YARN jobs (applications), such as Spark Streaming or Flink jobs, you must stop the jobs before you perform a rolling restart of the YARN NodeManagers.

  6. Restart services.

    To fully remediate the vulnerability, you must restart the affected components, including Hive, HDFS, Presto, Impala, Druid, Flink, Solr, Ranger, Storm, Oozie, Spark, and Zeppelin.

    To restart the Hive component, go to the Hive service page in the EMR console and choose More > Restart in the upper-right corner.

Gateway clusters

This remediation procedure relies on passwordless SSH access. For a gateway cluster, you must manually upload the patch package to each node in the cluster and follow the procedure for EMR clusters to apply the fix on each node.

Important
  • In the hosts file of the patch package, you need to enter only the hostname of the current node.

  • A gateway cluster does not run any component processes. Therefore, you do not need to restart any services after uploading the patch package.

New clusters and scale-outs

You can add a bootstrap action in the EMR console to automatically fix the vulnerability when you create an EMR cluster or scale out an existing cluster. Follow these steps:

  1. Click patches-log4j.tar.gz and bootstrap_log4j.sh to download the patch package and the bootstrap script, and then upload them to Object Storage Service (OSS).

    For example, the OSS paths of the files are oss://<bucket-name>/path/to/patches-log4j.tar.gz and oss://<bucket-name>/path/to/bootstrap_log4j.sh.

  2. Add a bootstrap action in the EMR console. For more information, see Manage bootstrap actions.

    In the Add Bootstrap Action dialog box, configure the parameters.

    Parameter

    Description

    Name

    The name of the bootstrap action. Example: fix-log4j-vulnerability.

    Script Address

    The OSS location of the script.

    The script path must be in the oss://**/*.sh format. In this example, use oss://<bucket-name>/path/to/bootstrap_log4j.sh.

    Parameter

    The parameter for the bootstrap action script, which specifies the values of variables that are referenced in the script.

    In this example, use oss://<bucket-name>/path/to/patches-log4j.tar.gz .

    Execution Scope

    Select Cluster.

    Execution Time

    Select After Component Startup.

    Execution Failure Policy

    Select Proceed.

  3. When scaling out an existing cluster, you only need to restart the corresponding components on the new nodes. If you create a new cluster, you must restart components such as HDFS, Hive, Presto, Impala, Druid, Flink, Solr, Ranger, Storm, Oozie, Spark, and Zeppelin.