Status
Impact
Upstream maintainers must cut a Hadoop release with the following changes to resolve this CVE. The fix has already been merged in PR #7524 (HADOOP-18991) which removes the unused commons-beanutils dependency entirely from Hadoop 3. The PR was merged on 2025-03-20. Spark depends on hadoop-client-runtime-3.4.1.jar which bundles this vulnerable dependency. Reference: https://github.com/apache/hadoop/pull/7524
Status