Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wgx7-jwwm-cgjv

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Improper Authentication in Apache Spark

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

Пакеты

Наименование

org.apache.spark:spark-parent_2.11

maven
Затронутые версииВерсия исправления

<= 2.4.5

2.4.6

Наименование

pyspark

pip
Затронутые версииВерсия исправления

< 2.4.6

2.4.6

EPSS

Процентиль: 100%
0.933
Критический

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 9.8
redhat
больше 5 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS3: 9.8
nvd
больше 5 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS3: 9.8
debian
больше 5 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's mas ...

CVSS3: 9.8
fstec
больше 5 лет назад

Уязвимость компонента Analytics Server программной платформы Oracle Business Intelligence Enterprise Edition, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 100%
0.933
Критический

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306