Логотип exploitDog
bind:CVE-2020-9480
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-9480

Количество 5

Количество 5

redhat логотип

CVE-2020-9480

больше 5 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2020-9480

больше 5 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2020-9480

больше 5 лет назад

In Apache Spark 2.4.5 and earlier, a standalone resource manager's mas ...

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-wgx7-jwwm-cgjv

почти 4 года назад

Improper Authentication in Apache Spark

CVSS3: 9.8
EPSS: Критический
fstec логотип

BDU:2025-09903

больше 5 лет назад

Уязвимость компонента Analytics Server программной платформы Oracle Business Intelligence Enterprise Edition, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-9480

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS3: 9.8
93%
Критический
больше 5 лет назад
nvd логотип
CVE-2020-9480

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS3: 9.8
93%
Критический
больше 5 лет назад
debian логотип
CVE-2020-9480

In Apache Spark 2.4.5 and earlier, a standalone resource manager's mas ...

CVSS3: 9.8
93%
Критический
больше 5 лет назад
github логотип
GHSA-wgx7-jwwm-cgjv

Improper Authentication in Apache Spark

CVSS3: 9.8
93%
Критический
почти 4 года назад
fstec логотип
BDU:2025-09903

Уязвимость компонента Analytics Server программной платформы Oracle Business Intelligence Enterprise Edition, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.8
93%
Критический
больше 5 лет назад

Уязвимостей на страницу