Package
celeborn-0.5
Component
commons-configuration2
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Status
Status
Impact
The vulnerable commons-configuration2 2.10.1 is shaded into the Apache Hadoop hadoop-client-runtime uber-jar (org.apache.hadoop.shaded.org.apache.commons.configuration2). The flaw is fixed in commons-configuration2 2.15.0, but Hadoop bundles 2.10.1 in all current releases (3.4.1, 3.4.2, 3.5.0) and on its development branch; because the classes are relocated inside the shaded jar, the version cannot be overridden downstream. Remediation is pending an Apache Hadoop release that bundles commons-configuration2 2.15.0 or later.
Status