Cumulative hotfix CDP Private Cloud Base 7.1.7.3013-1 (SP3 Cumulative hotfix4)

Know more about the cumulative hotfix 4 for CDP 7.1.7 SP3. This cumulative hotfix was released on Sep 06, 2024.

Following are the list of fixes that were shipped for CDP Private Cloud Base version 7.1.7-1.cdh7.1.7.p3013.57035125.

CDPD-73423: Ranger - Upgrade Spring Framework to 6.1.12/6.0.23/5.3.39 due to CVE-2024-38808 and CVE-2024-38809
Upgraded the Spring-framework version to 5.3.39 due to CVE-2024-38808 and CVE-2024-38809.
CDPD-72621: HWC - Support default constraints while writing into a table
Added support for default constraints while writing into a table in Hive Warehouse Connector.
CDPD-72292: [Private Cloud Releases] Upgrade RequireJS due to CVE-2024-38998 and CVE-2024-38999
Upgraded the RequireJS version due to CVE-2024-38998 and CVE-2024-38999.
CDPD-70357: Do not call HMS to get list of pruned partitions when translated filter is empty
Minimized the calls to Hive Metastore (HMS) layer to get the partitions list by making one call for each table irrespective of repetition.
CDPD-63092: Avro - CVE-2023-39410
When deserializing untrusted data, there was a possibility for a reader to consume memory beyond the allowed constraints, leading to out of memory on the system. This issue affected Java applications using Apache Avro Java SDK up to and including 1.11.2. This issue is resolved by updating to Apache-Avro version 1.11.3.
CDPD-66938: [Analyze] [Atlas] test_time_range tests fail
When the Apache Atlas server is running on a node which has time zone other than UTC, there might be a time of day when the search results might differ if the relative CreateTime date range filters of TODAY, YESTERDAY, etc. are used. For instance, if the server is in a different time zone from the user, TODAY may refer to different times than expected, causing mismatched results.
Use explicit date range filters instead of using relative date range filters, such as, TODAY, YESTERDAY.
CDPD-87670: [Atlas UI] Apache Atlas Glossary becomes unresponsive when the page size is set to 50
When the page limit is set to 50 in Glossary, the user interface becomes unresponsive due to an incorrect API call with the error message, when trying to show more than 25 associated entities for a glossary item: "expected type AtlasGlossaryCategory; found AtlasGlossaryTerm".

Apache Jira: ATLAS-5067

The Common Vulnerabilities and Exposures (CVEs) that are fixed in this CHF:
  • CVE-2024-36114 : Aircompressor
  • CVE-2024-38999 : RequireJS
  • CVE-2024-38998 : RequireJS
Table 1. Cloudera Runtime 7.1.7.3013 (Cumulative Hotfix 4) download URL:
Repository Location
https://[[***USERNAME***]]:[[***PASSWORD***]]@archive.cloudera.com/p/cdh7/7.1.7.3013/parcels/