Package
spark-4.0-scala-2.13
Component
jackson-databind
Latest update
8.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
spark-4.0 ships jackson-databind 2.18.8 directly (not affected). This advisory tracks the jackson-databind copy bundled inside a pre-built shaded uber-jar: hadoop-client-runtime-3.5.0.jar embeds 2.18.6 (fix: 2.18.8) and parquet-jackson-1.17.1.jar embeds 2.21.3 (fix: 2.21.4). Embedded dependencies of shaded artifacts cannot be updated independently; this requires new upstream Apache Hadoop / Apache Parquet releases with updated bundled jackson.
Status
Status