7.5
CVSS V3
Status
Justification
Impact
Upstream note that this is a false positive as it does not affect clients. See https://github.com/apache/druid/pull/13590
Status
Impact
This vulnerability relates to protobuf-java 3.7.1, included by the shaded JAR hadoop-client-runtime-3.3.6.jar.