Apache SparkGHSA-6mqq-8r44-vmjc
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
Medium4.7CVE-2018-1334 · Published Mar 14, 2019 · updated Oct 21, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pyspark PyPI | >= 2.2.0, < 2.2.2 | 2.2.2 |
| < 2.1.3 | 2.1.3 |
Details and references
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.
- CVSS 3.0
- CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- CVE-2018-1334, PYSEC-2018-25
- nvd.nist.gov/vuln/detail/CVE-2018-1334
- github.com/advisories/GHSA-6mqq-8r44-vmjc
- github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2018-25.yaml
- lists.apache.org/thread.html/4d6d210e319a501b740293daaeeeadb51927111fb8261a3e4cd60060@%3Cdev.spark.apache.org%3E
- spark.apache.org/security.html#CVE-2018-1334
More Apache Spark advisories
All Apache Spark| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 72019 | Pyspark User Impersonation Vulnerability CVE-2018-11760Medium5.5fixed in 2.2.3, 2.3.2 | Medium5.5 | 2.2.3, 2.3.2 |
| Nov 92018 | Apache Spark Deserialization of Untrusted Data vulnerability CVE-2017-12612High7.8fixed in 2.1.2 | High7.8 | 2.1.2 |
| Aug 82019 | Sensitive data written to disk unencrypted in Spark CVE-2019-10099High7.5fixed in 2.3.3 | High7.5 | 2.3.3 |
| Feb 102022 | Improper Authentication in Apache Spark CVE-2020-9480Critical9.8fixed in 2.4.6 | Critical9.8 | 2.4.6 |
| Mar 112022 | Authentication Bypass by Capture-replay in Apache Spark CVE-2021-38296High7.5fixed in 3.1.3 | High7.5 | 3.1.3 |
| Jul 192022 | Apache Spark UI can allow impersonation if ACLs enabled CVE-2022-33891High8.8fixed in 3.1.3, 3.2.2 | High8.8 | 3.1.3, 3.2.2 |