Package
spark-fips-4.1-scala-2.13
Component
jackson-databind
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
spark-fips-4.1 ships jackson-databind 2.21.4 directly (not affected). This advisory tracks the jackson-databind copy bundled inside a shaded uber-jar: hadoop-client-runtime-3.4.2-cg0.jar (embeds 2.12.7.1; produced by the hadoop-fips-3.4.2 package, where the fix must land) and parquet-jackson-1.17.1.jar (embeds 2.21.3; fix 2.21.4 requires a new Apache Parquet release). These cannot be updated from the spark-fips-4.1 build.
Status