Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-9480

Опубликовано: 22 июн. 2020
Источник: redhat
CVSS3: 9.8
EPSS Средний

Описание

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7apache-sparkNot affected
Red Hat Integration Camel K 1apache-sparkNot affected
Red Hat JBoss Data Grid 7apache-sparkNot affected
Red Hat JBoss Fuse 6apache-sparkNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1887887apache-spark: RCE vulnerability in auth-enabled standalone master

EPSS

Процентиль: 98%
0.2937
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS3: 9.8
debian
около 6 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's mas ...

CVSS3: 9.8
github
больше 4 лет назад

Improper Authentication in Apache Spark

CVSS3: 9.8
fstec
около 6 лет назад

Уязвимость компонента Analytics Server программной платформы Oracle Business Intelligence Enterprise Edition, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 98%
0.2937
Средний

9.8 Critical

CVSS3