Skip to content
Apache SparkGHSA-fvxv-9xxr-h7wj

Pyspark User Impersonation Vulnerability

Medium5.5CVE-2018-11760 · Published Feb 7, 2019 · updated Dec 4, 2024

When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.

GitHub advisory

Affected versions

PackageAffectedFixed in
pyspark
PyPI
>= 2.3.0, < 2.3.22.3.2
>= 1.0.2, < 2.2.32.2.3
Details and references

More Apache Spark advisories

All Apache Spark
Advisory
Apache Spark UI can allow impersonation if ACLs enabled
High8.8Jul 19, 2022
Authentication Bypass by Capture-replay in Apache Spark
High7.5Mar 11, 2022
Improper Authentication in Apache Spark
Critical9.8Feb 10, 2022
Sensitive data written to disk unencrypted in Spark
High7.5Aug 8, 2019
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
Medium4.7Mar 14, 2019
Apache Spark Deserialization of Untrusted Data vulnerability
High7.8Nov 9, 2018

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.