Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fp5j-3fpf-mhj5

Опубликовано: 08 авг. 2019
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Sensitive data written to disk unencrypted in Spark

Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchToMem); in SparkR, using parallelize; in Pyspark, using broadcast and parallelize; and use of python udfs.

Пакеты

Наименование

org.apache.spark:spark-core_2.11

maven
Затронутые версииВерсия исправления

< 2.3.3

2.3.3

Наименование

pyspark

pip
Затронутые версииВерсия исправления

< 2.3.3

2.3.3

EPSS

Процентиль: 67%
0.00542
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchToMem); in SparkR, using parallelize; in Pyspark, using broadcast and parallelize; and use of python udfs.

CVSS3: 7.5
debian
больше 6 лет назад

Prior to Spark 2.3.3, in certain situations Spark would write user dat ...

EPSS

Процентиль: 67%
0.00542
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-312