Логотип exploitDog
bind:CVE-2018-8024
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-8024

Количество 3

Количество 3

nvd логотип

CVE-2018-8024

больше 7 лет назад

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

CVSS3: 5.4
EPSS: Средний
debian логотип

CVE-2018-8024

больше 7 лет назад

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possib ...

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-8cw6-5qvp-q3wj

почти 7 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark via crafted URL

CVSS3: 5.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-8024

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

CVSS3: 5.4
44%
Средний
больше 7 лет назад
debian логотип
CVE-2018-8024

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possib ...

CVSS3: 5.4
44%
Средний
больше 7 лет назад
github логотип
GHSA-8cw6-5qvp-q3wj

Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark via crafted URL

CVSS3: 5.4
44%
Средний
почти 7 лет назад

Уязвимостей на страницу