Package
spark-4.1-scala-2.13
Component
jackson-databind
Latest update
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable classes are a relocated copy shaded into hadoop-client-runtime 3.5.0, the newest published release, which pins jackson 2.18.6. Dependency management cannot reach relocated coordinates, so remediation depends on an upstream release raising that pin above the fixed floor.
Status