Package
spark-fips-3.5-scala-2.13
Component
commons-configuration2
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
commons-configuration2 ≤2.10.1 is shaded into hadoop-client-runtime-3.3.6.jar via upstream apache/hadoop 3.3.6 pinning to 2.10.1. Apache trunk and release branches all still on 2.10.1.
Downstream bump blocked: cc2 2.15.x adds commons-io as a runtime dep, tripping apache/hadoop's hadoop-client-check-test-invariants banTransitiveDependencies enforcer. Fix requires upstream to bump + update invariants together.
Vuln requires untrusted YAML configs with cycles (CWE-674 DoS). Hadoop/Spark configs are XML-based, operator-controlled.
Status