Package
apache-polaris
Component
jline-reader
Latest update
5.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable jline classes are relocated/shaded inside a prebuilt third-party Hadoop client runtime jar; there is no direct dependency edge for a build-time version pin to intercept, and an existing dependency constraint on this same jar for an unrelated CVE has already proven ineffective against a live rescan.
Status