CVE Vulnerabilities

CVE-2018-11760

Published: Feb 04, 2019 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

When using PySpark , its possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.

Affected Software

Name Vendor Start Version End Version
Spark Apache 1.0.2 1.6.3
Spark Apache 2.0.0 2.0.2
Spark Apache 2.1.0 2.1.3
Spark Apache 2.2.0 2.2.2
Spark Apache 2.3.0 2.3.1

References