Skip to content
Apache SparkGHSA-6mqq-8r44-vmjc

Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark

Medium4.7CVE-2018-1334 · Published Mar 14, 2019 · updated Oct 21, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
pyspark
PyPI
>= 2.2.0, < 2.2.22.2.2
< 2.1.32.1.3
Details and references

In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.

CVSS 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
CVE-2018-1334, PYSEC-2018-25

More Apache Spark advisories

All Apache Spark
DateAdvisory
Feb 72019Pyspark User Impersonation Vulnerability
CVE-2018-11760Medium5.5fixed in 2.2.3, 2.3.2
Nov 92018Apache Spark Deserialization of Untrusted Data vulnerability
CVE-2017-12612High7.8fixed in 2.1.2
Aug 82019Sensitive data written to disk unencrypted in Spark
CVE-2019-10099High7.5fixed in 2.3.3
Feb 102022Improper Authentication in Apache Spark
CVE-2020-9480Critical9.8fixed in 2.4.6
Mar 112022Authentication Bypass by Capture-replay in Apache Spark
CVE-2021-38296High7.5fixed in 3.1.3
Jul 192022Apache Spark UI can allow impersonation if ACLs enabled
CVE-2022-33891High8.8fixed in 3.1.3, 3.2.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.