[Security] Upgrade Databricks JDBC Driver to resolve shaded jackson-core and httpcore5-h2 CVEs
Summary
The com.databricks:databricks-jdbc:3.3.3 driver bundles (shades) vulnerable transitive dependencies inside its JAR. Because these dependencies are shaded, they cannot be overridden via Maven dependency management and require a driver upgrade from Databricks.
Vulnerable Shaded Dependencies
[Security] Upgrade Databricks JDBC Driver to resolve shaded jackson-core and httpcore5-h2 CVEs
Summary
The
com.databricks:databricks-jdbc:3.3.3driver bundles (shades) vulnerable transitive dependencies inside its JAR. Because these dependencies are shaded, they cannot be overridden via Maven dependency management and require a driver upgrade from Databricks.Vulnerable Shaded Dependencies
com.fasterxml.jackson.core:jackson-core2.18.32.21.2org.apache.httpcomponents.core5:httpcore5-h25.2.45.3.5