7.5
CVSS V3
Status
Impact
This log4j dependency is a transitive dependency brought in from ambari-metrics-common-2.7.0.0.0.jar. This is the most recent version of ambari-metrics-common. To resolve this, upstream maintainers must release an updated version of ambari-metrics-common that contains the latest Log4j.
Status