Package
celeborn-0.7
Component
jackson-databind
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable jackson class is a relocated copy shaded inside Hadoop's hadoop-client-runtime uber-jar; it cannot be bumped independently. No released Hadoop, including 3.5.0 (jackson 2.18.6), ships a fixed jackson in that shaded artifact; Hadoop trunk pins 2.18.10. Pending an upstream Hadoop release carrying the fixed jackson.
Status
Previous location
/usr/share/java/celeborn/jars/hadoop-client-runtime-3.4.2.jarNew location
/usr/share/java/celeborn/jars/hadoop-client-runtime-3.4.3.jarImpact
version-only path change detected during APK rebuild
Status