Status
Impact
The version of hive-llap-common is not able to be upgraded from 2.3.9 to 4.0.0 due to version incompatibility with the parent dependency Hive, Spark-3.5 is only able to support Hive 2.3.9. To remediate this CVE would require Hive 4.0.0 which needs to be implemented by upstream maintainers. Upstream is targeting to remove this as part of the Spark-4.0.0 release as seen here: https://github.com/apache/spark/pull/49725
Status