/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-339m-c4h6-68cf

Published

Last updated

https://images.chainguard.dev/security/CGA-339m-c4h6-68cf
Package

spark-3.5

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-23454
  • GHSA-f5fw-25gw-5m92

Severity

6.2

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-23454

Updates

Status

Pending upstream fix

Impact

The changes required to implement an upgrade from hadoop 3.3.6 to hadoop 3.4.0 require core code changes which are set to be released as a part of the spark 4.0.0 release that is in preview now. PR can be found here: https://github.com/apache/spark/commit/49b4c3bc9c09325de941dfaf41e4fd3a4a4c345f

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing