Package
spark-4.0-scala-2.13
Component
jetty-http
Latest update
7.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Status
Impact
jetty-http 11.0.24 is bundled inside spark-core_2.13-4.0.3.jar and jetty-http 9.4.x inside the hadoop-client-runtime shaded jar. Eclipse Jetty 9.x is end-of-life and 11.x dead-ends at 11.0.26 on Maven Central; the GHSA's firstPatchedVersion 11.0.28 was never published. Resolution requires Hadoop and Spark upstreams to migrate to Jetty 12 (fixed at 12.0.33 / 12.1.7); Spark has done so on master but not the 4.x lines.
Status
Status
Impact
jetty-http 9.4.57.v20241219 is bundled inside hadoop-client-runtime-3.4.2.jar. Eclipse Jetty 9.x is end-of-life; the 11.x line caps at 11.0.26 on Maven Central with the GHSA's "firstPatchedVersion 11.0.28" not publicly available. Resolution requires Hadoop and Spark upstreams to upgrade their bundled jetty (likely to 12.x).
Status