CVE-2018-11760
published 2019-02-04CVE-2018-11760: When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This…
PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.60%
44.9th percentile
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | spark | — | — |
| apache | spark | 1.0.2 – 1.6.3 | — |
| apache | spark | 2.0.0 – 2.0.2 | — |
| apache | spark | 2.1.0 – 2.1.3 | — |
| apache | spark | 2.2.0 – 2.2.2 | — |
| apache | spark | 2.3.0 – 2.3.1 | — |
| apache_software_foundation | apache_spark | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_apache5.5HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Pyspark User Impersonation Vulnerability
ghsa·2019-02-07
CVE-2018-11760 [MEDIUM] Pyspark User Impersonation Vulnerability
Pyspark User Impersonation Vulnerability
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
OSV
Pyspark User Impersonation Vulnerability
osv·2019-02-07
CVE-2018-11760 [MEDIUM] Pyspark User Impersonation Vulnerability
Pyspark User Impersonation Vulnerability
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
OSV
CVE-2018-11760: When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark applicati
osv·2019-02-04
CVE-2018-11760 CVE-2018-11760: When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark applicati
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
Red Hat
spark: local priviledge escalation when using PySpark
vendor_redhat·2019-01-28·CVSS 5.5
CVE-2018-11760 [MEDIUM] CWE-284 spark: local priviledge escalation when using PySpark
spark: local priviledge escalation when using PySpark
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
Package: camel (Red Hat Fuse 7) - Not affected
Package: camel (Red Hat JBoss Fuse 6) - Out of support scope
Apache
Apache spark: CVE-2018-11760
vendor_apache·CVSS 5.5
CVE-2018-11760 [HIGH] Apache spark: CVE-2018-11760
Apache spark: CVE-2018-11760
Severity: Important Vendor: The Apache Software Foundation Versions affected: All Spark 1.x, Spark 2.0.x, and Spark 2.1.x versions Spark 2.2.0 to 2.2.2 Spark 2.3.0 to 2.3.1 Description: When using PySpark, it’s possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1. Mitigation: 1.x, 2.0.x, 2.1.x, and 2.2.x users should upgrade to 2.2.3 or newer 2.3.x users should upgrade to 2.3.2 or newer Otherwise, affected users should avoid using PySpark in multi-user environments. Credit: Luca Canali and Jose Carlos Luna Duran, CERN
Severity: high
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/106786https://lists.apache.org/thread.html/6d015e56b3a3da968f86e0b6acc69f17ecc16b499389e12d8255bf6e%40%3Ccommits.spark.apache.org%3Ehttps://lists.apache.org/thread.html/a86ee93d07b6f61b82b61a28049aed311f5cc9420d26cc95f1a9de7b%40%3Cuser.spark.apache.org%3Ehttp://www.securityfocus.com/bid/106786https://lists.apache.org/thread.html/6d015e56b3a3da968f86e0b6acc69f17ecc16b499389e12d8255bf6e%40%3Ccommits.spark.apache.org%3Ehttps://lists.apache.org/thread.html/a86ee93d07b6f61b82b61a28049aed311f5cc9420d26cc95f1a9de7b%40%3Cuser.spark.apache.org%3E
2019-02-04
Published