7.5
CVSS CVSS_V3
Status
Impact
Upstream maintainers must cut a Hadoop release with Avro 1.11.4 to resolve these CVEs. PR #7615 (HADOOP-19315) has been merged on 2025-04-15 which upgrades Avro from 1.9.2 to 1.11.4. This addresses both CVE-2024-47561 (critical severity) and CVE-2023-39410 (high severity) in the avro 1.9.2 dependency bundled within hadoop-client-runtime-3.4.1.jar. The PR notes this change is not backwards compatible due to Avro's requirement for setter/getter methods and serializable package declarations. Reference: https://github.com/apache/hadoop/pull/7615
Status