spark-3.4
Chainguard
9.8
CVSS V3
Status
Impact
Spark 3.4 has reached end of life (EOL), and new images are no longer being built. We strongly recommend upgrading to Spark 3.5 to ensure continued support and access to the latest updates.
Status
Impact
Spark-3.4 uses Derby 10.14.2.0 as after 10.17.1.0, the minimum required version is JDK19. Spark-3.4 uses JDK17 and the version of Derby in which this CVE is fixed has no plans for an official release at this time. The other version stream that would potentially be compatible with Spark-3.4 (10.16.x.x) also does not have an official release of Derby planned at this time that would fix the CVE.
Status
Status
Fixed version
3.4.3-r2Status
Status
Impact
This relates to protobuf-java v3.3.0 included by the shaded JARs mesos-1.4.3-shaded-protobuf.jar and hadoop-client-runtime-3.3.6.jar. There are no newer versions of these shaded JARs available to fix the vulnerability.