spark-3.5
Chainguard
Status
Impact
This commons-beanutils dependency is brought in as a transitive dependency via hadoop-client-runtime-3.3.6.jar. These transitive dependencies from hadoop-client-runtime-3.3.6.jar are not able to be upgraded to a higher version and require upstream maintainers to implement.
Status