CVE-2018-11804: Improper Input Validation
(updated )
The Apache Spark Maven-based build includes a convenience script, build/mvn
, that downloads and runs a zinc server to speed up compilation. It has been included in release branches since, up to and including master. This server will accept connections from external hosts by default. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build.
References
Detect and mitigate CVE-2018-11804 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →