Apache Spark Build Process Exposes Sensitive File Information
CVE-2018-11804
7.5HIGH
What is CVE-2018-11804?
Apache Spark features a convenience script, 'build/mvn', which facilitates a faster compilation by leveraging a zinc server. Unfortunately, this zinc server is configured to accept connections from external hosts by default, leading to a potential risk of exposing sensitive information. A crafted request to the server could allow unauthorized access to files that are readable by the developer account executing the build process. This issue uniquely impacts developers who are building Apache Spark from source, rather than end-users of the software. Timely updates and proper configuration are vital to mitigate the risks associated with this vulnerability.
Affected Version(s)
Apache Spark 1.3.0 < 3.*