QID 981255
QID 981255: Java (maven) Security Update for org.apache.spark:spark-core_2.11 (GHSA-6mqq-8r44-vmjc)
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6mqq-8r44-vmjc for updates pertaining to this vulnerability.
Vendor References
- GHSA-6mqq-8r44-vmjc -
github.com/advisories/GHSA-6mqq-8r44-vmjc
CVEs related to QID 981255
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6mqq-8r44-vmjc | org.apache.spark:spark-core_2.10 |
|
|
| GHSA-6mqq-8r44-vmjc | org.apache.spark:spark-core_2.11 |
|