QID 981097

QID 981097: Python (pip) Security Update for pyspark (GHSA-fvxv-9xxr-h7wj)

When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Customers are advised to refer to GHSA-fvxv-9xxr-h7wj for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981097

    Software Advisories
    Advisory ID Software Component Link
    GHSA-fvxv-9xxr-h7wj pyspark URL Logo github.com/advisories/GHSA-fvxv-9xxr-h7wj