/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-86x3-7p58-9qhp

Published

Last updated

https://images.chainguard.dev/security/CGA-86x3-7p58-9qhp
Package

spark-3.5-scala-2.13

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2019-0205
  • GHSA-rj7p-rfgp-852x

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2019-0205

Updates

Status

Pending upstream fix

Impact

This vulnerability relates to the 'libthrift' used by spark. A fixed version is available in v0.13.0. Upstream have upgraded to a fixed version in the main branch, but not back ported this to spark v3. Attempting to upgrade this dependency in spark v3 results in build failures, specifically compatibility issues with the 'maven-shade-plugin'. Separate attempts to update the maven-shade-plugin to a later version in parallel, did not resolve the issue. Awaiting for fix / backport from upstream to address this issue.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing