7.5
CVSS V3
Status
Impact
This vulnerability relates to the 'libthrift' used by spark. A fixed version is available in v0.13.0. Upstream have upgraded to a fixed version in the main branch, but not back ported this to spark v3. Attempting to upgrade this dependency in spark v3 results in build failures, specifically compatibility issues with the 'maven-shade-plugin'. Separate attempts to update the maven-shade-plugin to a later version in parallel, did not resolve the issue. Awaiting for fix / backport from upstream to address this issue.
Status