Local Privilege Escalation in Apache Spark by Impersonation Vulnerability
CVE-2018-1334
4.7MEDIUM
What is CVE-2018-1334?
In various versions of Apache Spark, a security vulnerability allows a malicious local user to connect to the Spark application. This could enable them to impersonate the user running the application, potentially leading to unauthorized access and actions within the Spark environment. This exposure highlights the importance of securing local peer connections and user interface configurations to mitigate related risks.
Affected Version(s)
Apache Spark 1.0.0 to 2.1.2
Apache Spark 2.2.0 to 2.2.1
Apache Spark 2.3.0