Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2018-8024

около 8 лет назад

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-8024

около 8 лет назад

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possib ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-8cw6-5qvp-q3wj

больше 7 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark via crafted URL

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-8024

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

CVSS3: 5.4
5%
Низкий
около 8 лет назад
debian логотип
CVE-2018-8024

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possib ...

CVSS3: 5.4
5%
Низкий
около 8 лет назад
github логотип
GHSA-8cw6-5qvp-q3wj

Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark via crafted URL

CVSS3: 5.4
5%
Низкий
больше 7 лет назад

Уязвимостей на страницу