Alibaba Cloud recently discovered a remote code execution (RCE) vulnerability in the Apache Log4j2 component and disclosed it to the Apache Software Foundation. This topic describes the impact of the vulnerability and the corresponding remediation plan.
Impact
In E-MapReduce (EMR), the affected components include Hive, Presto, Impala, Druid, Flink, Solr, Ranger, Storm, Oozie, Spark, and Zeppelin. Spark and Zeppelin are affected because they depend on the Hive component.
Remediation plan
You must replace the vulnerable Log4j2 JAR files in your EMR cluster with version 2.17.2 and modify the Hive and Spark Log4j configuration to disable the JNDI Lookup feature by setting log4j2.formatMsgNoLookups=true. For detailed instructions, see Remediation procedure.
This remediation plan has the following characteristics:
-
It applies to EMR-3.38.2 and earlier, EMR-5.4.2 and earlier, and EMR 4.x versions. The vulnerability is fixed in EMR-3.38.3 and later and EMR-5.4.3 and later. No action is required for these versions.
-
You must restart the corresponding components after applying this plan.
-
The remediation script does not impact your online services. However, because the fix only takes effect after the components are restarted, we recommend that you perform this procedure during off-peak hours.
Remediation procedure
EMR clusters
-
Click patches-log4j.tar.gz to download the patch package.
-
Log on to the master node of the EMR cluster, and place the patch package downloaded in Step 1 in the HOME directory of the
emr-userorhadoopuser. -
Decompress the patch package and run the following commands as the
emr-userorhadoopuser.-
For DataLake, Dataflow, OLAP, DataServing, and custom scenario clusters:
su emr-user tar zxf patches-log4j.tar.gz -
For other clusters:
su hadoop tar zxf patches-log4j.tar.gz
-
-
Edit the hosts file in the patch package to add the hostnames of all nodes in the cluster, such as emr-header-1 or emr-worker-1. Add one hostname per line.
cd patches vim hostsThe following is an example of the hosts file content:
emr-header-1 emr-worker-1 emr-worker-2ImportantFor clusters that run EMR 3.41 or later in the EMR 3.x series, or EMR 5.7.0 or later in the EMR 5.x series, the hostname format has changed. The following is an example of the hosts file content:
core-1-1 core-1-2 task-1-1 task-1-2 -
Run the fix.sh script to apply the fix.
./fix.shAfter the script runs, it returns the following message:
### NOTICE: YOU CAN RESTORE THIS PATCH BY RUN RESTORE SCRIPT ABOVE $> sh ./restore.sh 20211213001755 ### DONETo rollback the fix, run the following command:
./restore.sh 20211213001755NoteFor running YARN jobs (applications), such as Spark Streaming or Flink jobs, you must stop the jobs before you perform a rolling restart of the YARN NodeManagers.
-
Restart services.
To fully remediate the vulnerability, you must restart the affected components, including Hive, HDFS, Presto, Impala, Druid, Flink, Solr, Ranger, Storm, Oozie, Spark, and Zeppelin.
To restart the Hive component, go to the Hive service page in the EMR console and choose in the upper-right corner.
Gateway clusters
This remediation procedure relies on passwordless SSH access. For a gateway cluster, you must manually upload the patch package to each node in the cluster and follow the procedure for EMR clusters to apply the fix on each node.
-
In the hosts file of the patch package, you need to enter only the
hostnameof the current node. -
A gateway cluster does not run any component processes. Therefore, you do not need to restart any services after uploading the patch package.
New clusters and scale-outs
You can add a bootstrap action in the EMR console to automatically fix the vulnerability when you create an EMR cluster or scale out an existing cluster. Follow these steps:
-
Click patches-log4j.tar.gz and bootstrap_log4j.sh to download the patch package and the bootstrap script, and then upload them to Object Storage Service (OSS).
For example, the OSS paths of the files are oss://<bucket-name>/path/to/patches-log4j.tar.gz and oss://<bucket-name>/path/to/bootstrap_log4j.sh.
-
Add a bootstrap action in the EMR console. For more information, see Manage bootstrap actions.
In the Add Bootstrap Action dialog box, configure the parameters.
Parameter
Description
Name
The name of the bootstrap action. Example: fix-log4j-vulnerability.
Script Address
The OSS location of the script.
The script path must be in the oss://**/*.sh format. In this example, use oss://<bucket-name>/path/to/bootstrap_log4j.sh.
Parameter
The parameter for the bootstrap action script, which specifies the values of variables that are referenced in the script.
In this example, use oss://<bucket-name>/path/to/patches-log4j.tar.gz .
Execution Scope
Select Cluster.
Execution Time
Select After Component Startup.
Execution Failure Policy
Select Proceed.
-
When scaling out an existing cluster, you only need to restart the corresponding components on the new nodes. If you create a new cluster, you must restart components such as HDFS, Hive, Presto, Impala, Druid, Flink, Solr, Ranger, Storm, Oozie, Spark, and Zeppelin.