Package
spark-fips-3.5-scala-2.13
Component
jackson-databind
Latest update
8.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
spark-fips-3.5 ships jackson-databind 2.21.5 directly, and its hadoop-client-runtime-3.3.6-cg0.jar is rebuilt with shaded jackson 2.21.5 (hadoop-fips-3.3.6 epoch 23), as of 3.5.8-r4. This advisory tracks the jackson-databind copy bundled inside the prebuilt parquet-jackson-1.15.2.jar (shades 2.18.1). parquet >=1.17.x is Java-11 bytecode that the Java-8 spark 3.5 build cannot adopt (banned by spark's enforce-bytecode-version rule). Awaiting a Java-8-compatible parquet release bundling jackson >=2.21.4 (>=2.21.5 for CVE-2026-54515).
Status
Status