CVE-2018-1334
published 2018-07-12CVE-2018-1334: In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark…
PriorityP416medium4.7CVSS 3.0
AVLACHPRLUINSUCNIHAN
EPSS
0.50%
39.8th percentile
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | spark | <= 2.1.2 | — |
| apache | spark | — | — |
| apache | spark | — | — |
| apache | spark | 2.2.0 – 2.2.1 | — |
| apache_software_foundation | apache_spark | — | — |
| apache_software_foundation | apache_spark | — | — |
| apache_software_foundation | apache_spark | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
vendor_apache4.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
ghsa·2019-03-14
CVE-2018-1334 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
osv·2019-03-14
CVE-2018-1334 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.
OSV
CVE-2018-1334: In Apache Spark 1
osv·2018-07-12
CVE-2018-1334 CVE-2018-1334: In Apache Spark 1
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.
Apache
Apache spark: CVE-2018-1334
vendor_apache·CVSS 4.7
CVE-2018-1334 [HIGH] Apache spark: CVE-2018-1334
Apache spark: CVE-2018-1334
Severity: High Vendor: The Apache Software Foundation Versions affected: Spark versions through 2.1.2 Spark 2.2.0 to 2.2.1 Spark 2.3.0 Description: In Apache Spark up to and including 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it’s possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. Mitigation: 1.x, 2.0.x, and 2.1.x users should upgrade to 2.1.3 or newer 2.2.x users should upgrade to 2.2.2 or newer 2.3.x users should upgrade to 2.3.1 or newer Otherwise, affected users should avoid using PySpark and SparkR in multi-user environments. Credit: Nehmé Tohmé, Cloudera, Inc.
Severity: high
Affected versions: 2.1.2
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/4d6d210e319a501b740293daaeeeadb51927111fb8261a3e4cd60060%40%3Cdev.spark.apache.org%3Ehttps://spark.apache.org/security.html#CVE-2018-1334https://lists.apache.org/thread.html/4d6d210e319a501b740293daaeeeadb51927111fb8261a3e4cd60060%40%3Cdev.spark.apache.org%3Ehttps://spark.apache.org/security.html#CVE-2018-1334
2018-07-12
Published