spark-3.5
Chainguard
7.5
CVSS CVSS_V3
Status
Impact
This relates to avro v1.7, which is a transitive dependency of the shaded JAR hadoop-client-runtime, which is used by Spark. There are no newer versions of this shaded JAR available to fix the vulnerability.
Status