Package
hadoop-fips-3.3.6
Component
commons-configuration2
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
commons-configuration2 is bundled at the vulnerable 2.8.0 in hadoop-fips-3.3.6 — standalone and shaded into hadoop-client-runtime, hadoop-yarn-applications-catalog-webapp, and hadoop-benchmark. The fix lands in commons-configuration2 2.15.0, which ships as a multi-release JAR (META-INF/versions/9/module-info.class). Shading that into Hadoop's client uber-jars produces a duplicate module-info.class that fails Apache Hadoop's hadoop-client-check-test-invariants BanDuplicateClasses packaging check, so the version cannot be advanced without a shading-compatible change. Pending an upstream Apache Hadoop release shipping a fixed commons-configuration2 (or making the client-jar shading multi-release-aware).
Status