Package
ranger
Component
commons-configuration2
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
commons-configuration2 2.10.1 is shaded inside hadoop-client-runtime-3.4.3.jar; the top-level copy is already pinned to the fixed 2.15.0. Hadoop still pins 2.10.1 as of 3.5.0. A fix requires upstream Hadoop to upgrade their bundled commons-configuration2 to >= 2.15.0.
Status