5.9
CVSS CVSS_V3
Status
Impact
This vulnerability relates to 'guava', one of spark's dependencies. Remediating this requires upgrading guava to v24.1.1 or higher, which is a significant version upgrade. Spark has already upgraded to a fixed version in the main branch, but this is yet to be backported to the spark v3.5 release. Attempting to upgrade guava results in build issues. For more information, see: https://issues.apache.org/jira/browse/SPARK-38262 https://github.com/apache/spark/pull/36231
Status