/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-57ph-jjfx-2q7m

Published

Last updated

https://images.chainguard.dev/security/CGA-57ph-jjfx-2q7m
Package

spark-3.4

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2020-13949
  • GHSA-g2fg-mr77-6vrm

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2020-13949

Updates

Status

Fix not planned

Impact

Spark 3.4 has reached end of life (EOL), and new images are no longer being built. We strongly recommend upgrading to Spark 3.5 to ensure continued support and access to the latest updates.

Status

Pending upstream fix

Impact

Due to API changes in libthrift from .12 to a fix version requires implementation of Hive to 2.3.10 from 2.3.9. There is a test PR open where the upstream maintainers have attempted to implement in 3.4.x however due to extensive changes it has been targeted to be a part of the spark 4.0.0 release https://github.com/apache/spark/pull/45372

Status

Under investigation

Status

Pending upstream fix

Impact

Spark v3.5.0 is incompatible with higher versions of libthrift. https://github.com/apache/spark/pull/34878


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing