7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
Upstream note that this is a false positive as it does not affect clients. See https://github.com/apache/druid/pull/13590
Status
Impact
This vulnerability relates to protobuf-java 3.7.1, included by the shaded JAR hadoop-client-runtime-3.3.6.jar.