One of our client recently performed a vulnerability scan on Splunk Enterprise 8.2.7 and they were found as vulnerable for Apache Spark package and Apache hive package :
bin\jars\vendors\spark\3.0.1\lib\spark-core_2.12-3.0.1.jar
and
\bin\jars\thirdparty\hive_3_1\hive-exec-3.1.2.jar
I see version 9.0 uses patched version of hive i.e 3.1.3 and does not use spark
Did anyone else found this ??