PT-2018-11764 · Apache · Apache Spark

Nehmã© Tohmã©

·

Published

2018-07-12

·

Updated

2019-03-14

·

CVE-2018-1334

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Spark versions 1.0.0 through 2.1.2 Apache Spark versions 2.2.0 through 2.2.1 Apache Spark version 2.3.0
Description The issue allows a different local user to connect to the Spark application and impersonate the user running the application when using PySpark or SparkR.
Recommendations For Apache Spark versions 1.0.0 through 2.1.2, update to a version outside of this range to resolve the issue. For Apache Spark versions 2.2.0 through 2.2.1, update to a version outside of this range to resolve the issue. For Apache Spark version 2.3.0, update to a version later than 2.3.0 to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1334
GHSA-6MQQ-8R44-VMJC
PYSEC-2018-25

Affected Products

Apache Spark