⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.
Severity
9.8CRITICAL
EPSS
90.6%
top 0.39%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJun 23
Latest updateFeb 10

Description

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

NVDapache/spark2.4.5
CVEListV5apache_software_foundation/apache_sparkApache Spark 2.4.5 and earlier
PyPIpyspark< 2.4.6

Patches

🔴Vulnerability Details

5
GHSA
Improper Authentication in Apache Spark2022-02-10
OSV
Improper Authentication in Apache Spark2022-02-10
OSV
CVE-2020-9480: In Apache Spark 22020-06-23
CVEList
CVE-2020-9480: In Apache Spark 22020-06-23
VulnCheck
Apache spark Missing Authentication for Critical Function2020

💥Exploits & PoCs

1
Nuclei
Apache Spark - Authentication Bypass

🔍Detection Rules

3
Suricata
ET EXPLOIT Apache Spark RPC - Unauthenticated RegisterApplication Request (CVE-2020-9480)2022-01-28
Suricata
ET ATTACK_RESPONSE Apache Spark RPC - Unauthenticated RegisterApplication - Successfully Registered (CVE-2020-9480)2022-01-28
Suricata
ET EXPLOIT Apache Spark RPC - Unauthenticated RegisterApplication Request - RCE Attempt (CVE-2020-9480)2022-01-28

📋Vendor Advisories

3
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Server (Apache Spark) — CVE-2020-94802021-04-15
Red Hat
apache-spark: RCE vulnerability in auth-enabled standalone master2020-06-22
Apache
Apache spark: CVE-2020-9480

💬Community

1
Bugzilla
CVE-2020-9480 apache-spark: RCE vulnerability in auth-enabled standalone master2020-10-13
CVE-2020-9480 (CRITICAL CVSS 9.8) | In Apache Spark 2.4.5 and earlier | cvebase.io