PyPi: Spark-On-K8s

CVE-2024-34064

Transitive

Safety vulnerability ID: 70903

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at May 06, 2024 Updated at Jul 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Spark-on-k8s version 0.7.1 upgrades Jinja2 from 3.1.3 to 3.1.4 to address the security issue identified in CVE-2024-34064.

Affected package

spark-on-k8s

Latest version: 0.10.1

A Python package to submit and manage Apache Spark applications on Kubernetes.

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* fix(airflow): configure provider metadata to make the extra-link discoverable by hussein-awala in https://github.com/hussein-awala/spark-on-k8s/pull/60
* security: bump Jinja2 to avoid CVE-2024-34064 by hussein-awala in https://github.com/hussein-awala/spark-on-k8s/pull/61


**Full Changelog**: https://github.com/hussein-awala/spark-on-k8s/compare/0.7.0...0.7.1

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application