Skip to content
Apache SparkGHSA-fp5j-3fpf-mhj5

Sensitive data written to disk unencrypted in Spark

High7.5CVE-2019-10099 · Published Aug 8, 2019 · updated Oct 24, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
pyspark
PyPI
< 2.3.32.3.3
Details and references

Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchToMem); in SparkR, using parallelize; in Pyspark, using broadcast and parallelize; and use of python udfs.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-312
Also known as
CVE-2019-10099, PYSEC-2019-114

More Apache Spark advisories

All Apache Spark
DateAdvisory
Mar 142019Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
CVE-2018-1334Medium4.7fixed in 2.1.3, 2.2.2
Feb 72019Pyspark User Impersonation Vulnerability
CVE-2018-11760Medium5.5fixed in 2.2.3, 2.3.2
Nov 92018Apache Spark Deserialization of Untrusted Data vulnerability
CVE-2017-12612High7.8fixed in 2.1.2
Feb 102022Improper Authentication in Apache Spark
CVE-2020-9480Critical9.8fixed in 2.4.6
Mar 112022Authentication Bypass by Capture-replay in Apache Spark
CVE-2021-38296High7.5fixed in 3.1.3
Jul 192022Apache Spark UI can allow impersonation if ACLs enabled
CVE-2022-33891High8.8fixed in 3.1.3, 3.2.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.