Package
spark-4.2-scala-2.13
Component
jline-reader
Latest update
5.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
hadoop-client-runtime-3.5.0.jar is Apache Hadoop's own pre-built shaded uber-jar, published as-is to Maven Central; Spark never recompiles it. Its jline-reader classes are relocated to org.apache.hadoop.shaded.org.jline.reader but retain the original META-INF/maven/org.jline/jline-reader/pom.properties, which is what the scanner keys off at version 3.9.0. Verified by extracting the jar: no other class in hadoop-client-runtime references org.apache.hadoop.shaded.org.jline.reader (checked via binary grep across all .class files), and the jar has no Main-Class or CLI entry point of its own. The vulnerable DefaultHistory.matchPatterns ReDoS is therefore dead code in this artifact -- nothing in Hadoop's client-runtime library ever invokes it. Note: the same CVE also affects a genuinely-reachable copy at /usr/lib/spark/jars/jline-3.29.0-jdk8.jar, a real unshaded org.jline:jline artifact likely used by spark-shell's interactive REPL -- that component location is intentionally NOT covered by this event and remains open pending an actual fix.
Status