7.5
CVSS V3
Status
Impact
The vulnerability is introduced through a transient dependency carried by Hadoop v3.4.1. Upstream needs to provide a proper fix; once that is available, we can upgrade and remediate the CVE. In the meantime, we have proactively upgraded all io.netty dependencies to v4.1.125, the patched version.
Status