CVE-2018-8024
Summary
| CVE | CVE-2018-8024 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-12 13:29:00 UTC |
| Updated | 2023-11-07 03:01:00 UTC |
| Description | In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security | Apache Spark | CONFIRM | spark.apache.org | Mitigation, Vendor Advisory |
| Apache Mail Archives | MLIST | lists.apache.org | Mailing List, Mitigation, Vendor Advisory |
| Apache Mail Archives | lists.apache.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981203 Java (maven) Security Update for org.apache.spark:spark-core_2.11 (GHSA-8cw6-5qvp-q3wj)