9.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
This is a transitive dependency of com.netflix.astyanax:astyanax:jar. It will need to be mitigated by the upstream maintainers.
Status
Impact
This vulnerability relates to Netty 3.10.6, a transitive dependency of the shaded JAR ambari-metrics-emitter used by Druid. No newer versions of this shaded JAR are available to fix the vulnerability.
Status