Package
celeborn-0.5
Component
jline-reader
Latest update
5.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable jline classes are shaded inside a prebuilt third-party Hadoop client runtime jar pulled transitively from Maven Central; there is no direct dependency edge for a build-time version pin to intercept. The Hadoop release line that ships a fixed jline requires Java 17, while the current release requires Java 11 -- Java 17 support arrives only in a later major release. Revisit once a compatible Java-17 release is available or the Hadoop client runtime backports the jline fix.
Status