Description
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0111 | When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1. |
Github GHSA |
GHSA-fvxv-9xxr-h7wj | Pyspark User Impersonation Vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T19:19:24.731Z
Reserved: 2018-06-05T00:00:00.000Z
Link: CVE-2018-11760
No data.
Status : Modified
Published: 2019-02-04T17:29:00.280
Modified: 2024-11-21T03:43:58.443
Link: CVE-2018-11760
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA