Package
spark-3.5-scala-2.12
Component
jackson-databind
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
spark-3.5 bundles parquet-jackson 1.15.2 (shades jackson 2.18.1, fixed for this CVE) and ships jackson-databind 2.21.5 directly as of 3.5.8-r16. The remaining vulnerable copy is jackson-databind 2.12.7.1 shaded inside the prebuilt hadoop-client-runtime-3.3.6.jar. No hadoop 3.3.x release bundles jackson >=2.14, and hadoop >=3.5.0 is Java-11 bytecode that the Java-8 spark 3.5 build cannot adopt. Awaiting an upstream hadoop release bundling a fixed jackson.
Status