Uploaded image for project: 'Spark'
  1. Spark
  2. SPARK-39793

How to treat/eliminate CVE-2021-4048 (reported for arpack_combined_all-0.1.jar)

Attach filesAttach ScreenshotAdd voteVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Question
    • Status: Open
    • Major
    • Resolution: Unresolved
    • 3.3.0
    • None
    • MLlib
    • None

    Description

      The following CVE is reported for arpack_combined_all-0.1.jar which is used inĀ  org.apache.spark:spark-graphx_2.13 which in turn is used in mllib : https://nvd.nist.gov/vuln/detail/CVE-2021-4048

      Questions: how relevant is this issue, can it be safely ignored?

      It seems that arpack_combined_all-0.1.jar is really needed because when removing it from the CLASSPATH, a NoClassDefFoundError: org/netlib/blas/Sdot is reported.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            Unassigned Unassigned
            alexnb Alexander Bouriakov

            Dates

              Created:
              Updated:

              Slack

                Issue deployment