/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-cch5-m8vc-66rh

Published

Last updated

https://images.chainguard.dev/security/CGA-cch5-m8vc-66rh
Package

spark-3.5

RepositoryWolfi
Latest Update
Fix not planned
Aliases
  • CVE-2022-46337
  • GHSA-rcjc-c4pj-xxrp

Severity

9.8

Critical

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-46337

Updates

Status

Fix not planned

Impact

This relates to 'derby',Spark-3.5 currently uses version 10.14.2.0, while the closest fixed version available in the Maven Central repository is 10.17.1.0. However, this version requires a minimum of Java 17 to build, whereas Spark-3.5 is built with Java 8 and 11 as well. Upgrading to 10.17.1.0 would cause a build break due to Java bytecode version incompatibility. At this time, we are not planning to upgrade the version of Derby in Spark-3.5. The upstream project has updated to version 10.16.1.1, which does not resolve the vulnerability. The upstream is currently waiting for a backport to Derby version 10.16.2.x which they have planed to fix in version spark-4 or later. For reference, see: https://github.com/apache/spark/pull/44174

Status

Under investigation

Status

Fixed

Fixed version

3.5.2-r2

Status

Pending upstream fix

Impact

This relates to 'derby'. Various fixes where commmitted to main branch in Dec 2023 but we are waiting for a release to be created with these changes. https://github.com/apache/spark/pull/44174

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing