CVE Vulnerabilities

CVE-2018-11760

Published: Feb 04, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu

When using PySpark , its possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.

Affected Software

Name Vendor Start Version End Version
Spark Apache 1.0.2 (including) 1.6.3 (including)
Spark Apache 2.0.0 (including) 2.0.2 (including)
Spark Apache 2.1.0 (including) 2.1.3 (including)
Spark Apache 2.2.0 (including) 2.2.2 (including)
Spark Apache 2.3.0 (including) 2.3.1 (including)

References