Package
spark-fips-3.5-scala-2.13
Component
commons-configuration2
Latest update
5.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
This relates to commons-configuration2 2.8.0 included by the shaded JARs hadoop-client-runtime-3.3.6.jar. Spark is planning an upgrade to Hadoop 3.4.0 for Spark 4.0.0, but as of today, the shaded JAR for Hadoop 3.4.0 still includes this vulnerability. [v2-migration]
Status
Status
Fixed version
3.5.4-r18Status
Impact
This relates to commons-configuration2 2.8.0 included by the shaded JARs hadoop-client-runtime-3.3.6.jar. Spark is planning an upgrade to Hadoop 3.4.0 for Spark 4.0.0, but as of today, the shaded JAR for Hadoop 3.4.0 still includes this vulnerability.
Status