PT-2018-10829 · Apache · Apache Spark

Andre Protas

·

Publicado

2018-10-24

·

Atualizado

2024-06-10

·

CVE-2018-11804

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Spark versions 1.3.x through master
Description The issue concerns a convenience script in Apache Spark's Apache Maven-based build that downloads and runs a zinc server to speed up compilation. This server accepts connections from external hosts by default. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build. Note that this issue does not affect end users of Spark, only developers building Spark from source code.
Recommendations For versions 1.3.x through master, consider disabling the zinc server or restricting its access to prevent external connections until a patch is available. As a temporary workaround, restrict access to the build/mvn script to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11804
GHSA-62G2-M955-V383

Produtos afetados

Apache Spark