Updated on 2024-08-28 GMT+08:00

Remediating Manager NodeAgent

Prerequisites

You have obtained the URL and admin account for logging in to FusionInsight Manager.

Procedure

  1. Log in to the active OMS node as user omm and back up the $NODE_AGENT_HOME/bin/nodeagent_ctl.sh file.

    cp $NODE_AGENT_HOME/bin/nodeagent_ctl.sh /tmp

  2. Run the vi $NODE_AGENT_HOME/bin/nodeagent_ctl.sh command, find the line where JVM_ARGS= is located, and add the following content below the line:

    JVM_ARGS="$JVM_ARGS -Dfastjson.parser.safeMode=true"

  3. Perform 1 and 2 on all nodes in the cluster.

    You can manually overwrite the modified $NODE_AGENT_HOME/bin/nodeagent_ctl.sh file on all nodes as user omm.

  4. Run the following command on the active OMS node as user omm to restart all NodeAgents in the cluster:

    $CONTROLLER_HOME/inst/restartAllNoes.sh

  5. Log in to the cluster node to check the process.

    ps -ef |grep NodeAgent

    If the -Dfastjson.parser.safeMode=true parameter exists, the vulnerability has been mitigated.