Package
druid
Component
druid
Latest update
Fixed version
35.0.1-r1
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
35.0.1-r1Status
Impact
This vulnerability relates to log4j 1.2.17, a transitive dependency of the shaded JAR ambari-metrics-emitter used by Druid. No newer versions of this shaded JAR are available to fix the vulnerability.