CVE-2021-38296
published 2022-03-10CVE-2021-38296: Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.82%
76.3th percentile
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | spark | < 3.1.3 | 3.1.3 |
| apache | spark | — | — |
| apache_software_foundation | apache_spark | up to and including version 3.1.2 – 3.1.2 | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache7.5
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Authentication Bypass by Capture-replay in Apache Spark
osv·2022-03-11
CVE-2021-38296 [HIGH] Authentication Bypass by Capture-replay in Apache Spark
Authentication Bypass by Capture-replay in Apache Spark
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later
GHSA
Authentication Bypass by Capture-replay in Apache Spark
ghsa·2022-03-11
CVE-2021-38296 [HIGH] CWE-294 Authentication Bypass by Capture-replay in Apache Spark
Authentication Bypass by Capture-replay in Apache Spark
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later
OSV
CVE-2021-38296: Apache Spark supports end-to-end encryption of RPC connections via "spark
osv·2022-03-10
CVE-2021-38296 CVE-2021-38296: Apache Spark supports end-to-end encryption of RPC connections via "spark
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Spark) — CVE-2021-38296
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2021-38296 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Spark) — CVE-2021-38296
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Spark) vulnerability
CVE: CVE-2021-38296
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Apache
Apache spark: CVE-2021-38296
vendor_apache·CVSS 7.5
CVE-2021-38296 Apache spark: CVE-2021-38296
Apache spark: CVE-2021-38296
Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Spark 3.1.2 and earlier Description: Apache Spark supports end-to-end encryption of RPC connections via spark.authenticate and spark.network.crypto.enabled . In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by spark.authenticate.enableSaslEncryption , spark.io.encryption.enabled , spark.ssl , spark.ui.strictTransportSecurity . Mitigation: Update to Spark 3.1.3 or later Credit: Steve Weis (Databricks)
Severity: moderate
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-10
Published