Package
spark-4.1-scala-2.13
Component
commons-configuration2
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
commons-configuration2 ≤2.10.1 is shaded into upstream-built hadoop-client-runtime-X.Y.Z.jar (no -cgN suffix) from apache/hadoop. Hadoop pins commons-configuration2 to 2.10.1 in hadoop-project/pom.xml.
Apache Hadoop trunk + rel/release-3.3.6 + rel/release-3.4.2 all still pin to 2.10.1; zero open apache/hadoop PRs target the 2.15.x line.
This non-FIPS spark builds against upstream apache/hadoop via Maven Central — no downstream pombump path can affect the shaded JAR. Resolution requires upstream apache/hadoop to bump.
Vuln requires untrusted YAML configs with reference cycles (CWE-674 DoS). Spark configs are XML-based, operator-controlled.
Status
Status
Impact
commons-configuration2 ≤2.10.1 is shaded into upstream-built hadoop-client-runtime-X.Y.Z.jar (no -cgN suffix) from apache/hadoop. Hadoop pins commons-configuration2 to 2.10.1 in hadoop-project/pom.xml.
Apache Hadoop trunk + rel/release-3.3.6 + rel/release-3.4.2 all still pin to 2.10.1; zero open apache/hadoop PRs target the 2.15.x line.
This non-FIPS spark builds against upstream apache/hadoop via Maven Central — no downstream pombump path can affect the shaded JAR. Resolution requires upstream apache/hadoop to bump.
Vuln requires untrusted YAML configs with reference cycles (CWE-674 DoS). Spark configs are XML-based, operator-controlled.
Status