9.8
CVSS V3
Status
Fixed version
0.10.4-r8Status
Status
Fixed version
0.10.4-r6Status
Impact
The dependency responsible for this CVE is a transitive dependency where the version of said dependency is not explicitly defined in the project but rather brought in under the hadoop-client-runtime jar. This requires upstream maintainers to implement a fix.
Status