Package
spark-3.5-scala-2.13
Component
guava
Latest update
Fixed version
3.5.7-r2
5.9
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
3.5.7-r2Status
Impact
This vulnerability relates to 'guava', one of spark's dependencies. Remediating this requires upgrading guava to v24.1.1 or higher, which is a significant version upgrade. Spark has already upgraded to a fixed version in the main branch, but this is yet to be backported to the spark v3.5 release. Attempting to upgrade guava results in build issues. For more information, see: https://issues.apache.org/jira/browse/SPARK-38262 https://github.com/apache/spark/pull/36231
Status