Package
spark-4.1-scala-2.13
Component
jackson-databind
Latest update
Fixed version
4.1.3-r3
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
4.1.3-r3Status
Impact
The vulnerable classes are a relocated copy shaded into parquet-jackson 1.17.1, the newest published release, which carries jackson 2.21.3. Dependency management cannot reach relocated coordinates, so remediation depends on an upstream release; the raise to 2.22.1 is committed upstream but not yet released.
Status