When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0111 | When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1. |
Github GHSA |
GHSA-fvxv-9xxr-h7wj | Pyspark User Impersonation Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T19:19:24.731Z
Reserved: 2018-06-05T00:00:00
Link: CVE-2018-11760
No data.
Status : Modified
Published: 2019-02-04T17:29:00.280
Modified: 2024-11-21T03:43:58.443
Link: CVE-2018-11760
OpenCVE Enrichment
No data.
EUVD
Github GHSA