Does CVE-2020-13949 (vulnerability) affect the data plane and its security patch is included in Databricks 10.4 LTS?

JH
New Contributor II

Here is the previous discussion.

https://community.databricks.com/s/question/0D58Y0000ACcIv2SQF/does-thrift-only-exist-in-databrick-c...

 

I have the following questions.

  1. Does CVE-2020-13949 affect the data plane or not?
  2. Do you know from which version of Databricks runtime you begin to have the patch for this vulnerability? Or is it confirmed that the patch for this vulnerability is included in Databricks runtime 10.4 LTS?

Thanks.