Local Privilege Escalation in Apache Spark by Impersonation Vulnerability
CVE-2018-1334

4.7MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
12 July 2018

Summary

In various versions of Apache Spark, a security vulnerability allows a malicious local user to connect to the Spark application. This could enable them to impersonate the user running the application, potentially leading to unauthorized access and actions within the Spark environment. This exposure highlights the importance of securing local peer connections and user interface configurations to mitigate related risks.

Affected Version(s)

Apache Spark 1.0.0 to 2.1.2

Apache Spark 2.2.0 to 2.2.1

Apache Spark 2.3.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.