It looks that the existing pinot-orc package has some library dependency that contains some security concerns. We should check the dependency graph and check if the version bump would fix the issue.
net.minidev:json-smart
org.apache.hadoop:hadoop-common
com.fasterxml.woodstox:woodstox-core