CVE Vulnerabilities

CVE-2018-11760

Published: Feb 04, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

When using PySpark , its possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.

Affected Software

NameVendorStart VersionEnd Version
SparkApache1.0.2 (including)1.6.3 (including)
SparkApache2.0.0 (including)2.0.2 (including)
SparkApache2.1.0 (including)2.1.3 (including)
SparkApache2.2.0 (including)2.2.2 (including)
SparkApache2.3.0 (including)2.3.1 (including)

References