Package
pinot
Component
jline-remote-telnet
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable jline code is bundled inside the hadoop-client-runtime uber jar shipped by the Parquet input-format plugin. That jar is a prebuilt artifact published by Apache Hadoop that internally relocates jline 3.9.0, so it cannot be advanced through dependency management in this build. No released Apache Hadoop version ships jline 4.2.1 or later; remediation requires an upstream Hadoop release that updates its bundled jline.
Status
Status