@Jimin Hsieh :
CVE-2020-13949 is a vulnerability in the Apache Thrift library, which is used in the Databricks control plane to manage clusters and other resources. Therefore, it does not directly affect the data plane of Databricks clusters. However, as a security vulnerability in a component used by the control plane, it could potentially be used to compromise the security of the entire Databricks environment if left unpatched.
Databricks has released patches for this vulnerability and recommends that users update to a version that includes the patch. The patch is included in Databricks Runtime 7.3 and later versions. It is not clear whether the patch is included in Databricks Runtime 10.4 LTS specifically, as the LTS versions may have additional backported security fixes. I recommend reaching out to Databricks support to confirm the patch status for your specific use case.