Apache Spark vulnerabilities
22 known vulnerabilities affecting apache/spark.
Total CVEs
22
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH8MEDIUM11
Vulnerabilities
Page 2 of 2
CVE-2018-11760P4MEDIUMCVSS 5.5≥ 1.0.2, ≤ 1.6.3≥ 2.0.0, ≤ 2.0.2+3 more2019-02-04
CVE-2018-11760 [MEDIUM] CVE-2018-11760: When using PySpark , it's possible for a different local user to connect to the Spark application an
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
nvd
CVE-2018-1334P4MEDIUMCVSS 4.7≤ 2.1.2≥ 2.2.0, ≤ 2.2.1+1 more2018-07-12
CVE-2018-1334 [MEDIUM] CWE-200 CVE-2018-1334: In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possib
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.
nvd
← Previous2 / 2