Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-9480

Опубликовано: 23 июн. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 9.3
EPSS Средний

Описание

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:*
Версия до 2.4.5 (включая)
Конфигурация 2
cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise:*:*:*

EPSS

Процентиль: 98%
0.2937
Средний

9.8 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
redhat
около 6 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS3: 9.8
debian
около 6 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's mas ...

CVSS3: 9.8
github
больше 4 лет назад

Improper Authentication in Apache Spark

CVSS3: 9.8
fstec
около 6 лет назад

Уязвимость компонента Analytics Server программной платформы Oracle Business Intelligence Enterprise Edition, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 98%
0.2937
Средний

9.8 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-306