CVE-2018-11760: Pyspark User Impersonation Vulnerability
(updated )
When using PySpark , it’s possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
References
- github.com/advisories/GHSA-fvxv-9xxr-h7wj
- github.com/apache/spark
- github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2019-169.yaml
- lists.apache.org/thread.html/6d015e56b3a3da968f86e0b6acc69f17ecc16b499389e12d8255bf6e@%3Ccommits.spark.apache.org%3E
- lists.apache.org/thread.html/a86ee93d07b6f61b82b61a28049aed311f5cc9420d26cc95f1a9de7b@%3Cuser.spark.apache.org%3E
- nvd.nist.gov/vuln/detail/CVE-2018-11760
- web.archive.org/web/20200227091119/http://www.securityfocus.com/bid/106786
- web.archive.org/web/20200925111106/https://issues.apache.org/jira/browse/SPARK-26802
Detect and mitigate CVE-2018-11760 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →