MEDIUM 4.7 Maven
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
GHSA-6mqq-8r44-vmjc · CVE-2018-1334 · PYSEC-2018-25
Published · Modified
Description
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2018-1334
- ADVISORY https://github.com/advisories/GHSA-6mqq-8r44-vmjc
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2018-25.yaml
- WEB https://lists.apache.org/thread.html/4d6d210e319a501b740293daaeeeadb51927111fb8261a3e4cd60060@%3Cdev.spark.apache.org%3E
- WEB https://spark.apache.org/security.html#CVE-2018-1334
Ready to move
Start Securing
Free, no credit card | First findings in minutes