Skip to content
Apache SparkGHSA-wgx7-jwwm-cgjv

Improper Authentication in Apache Spark

Critical9.8CVE-2020-9480 · Published Feb 10, 2022 · updated Oct 15, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
pyspark
PyPI
< 2.4.62.4.6
Details and references

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287, CWE-306
Also known as
BIT-spark-2020-9480, CVE-2020-9480, PYSEC-2020-95

More Apache Spark advisories

All Apache Spark
DateAdvisory
Mar 112022Authentication Bypass by Capture-replay in Apache Spark
CVE-2021-38296High7.5fixed in 3.1.3
Jul 192022Apache Spark UI can allow impersonation if ACLs enabled
CVE-2022-33891High8.8fixed in 3.1.3, 3.2.2
Nov 12022Apache Spark vulnerable to Log Injection
CVE-2022-31777Medium5.4fixed in 3.2.2, 3.3.1
Apr 172023Apache Spark vulnerable to Improper Privilege Management
CVE-2023-22946Critical9.9fixed in 3.3.2, 3.3.3
May 22023Apache Spark UI vulnerable to Command Injection
CVE-2023-32007High8.8fixed in 3.2.2
Aug 82019Sensitive data written to disk unencrypted in Spark
CVE-2019-10099High7.5fixed in 2.3.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.