What version of log4j is used in pyspark 3.2.0?
We need to identify this version in order to mitigate the CVE-2021-44228 vulnerability.
What version of log4j is used in pyspark 3.2.0?
We need to identify this version in order to mitigate the CVE-2021-44228 vulnerability.
Apache Spark 3.2.0 release version uses log4j 1.2.17 OOTB (see "Compile Dependencies" section in https://mvnrepository.com/artifact/org.apache.spark/spark-core_2.12/3.2.0). It's not exposed to the "CVE-2021-44228" vulnerability (as is currently known) but also cannot be treated as "completely safe" because of the eldest weaknesses (e.g. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17571).