Sensitive information sent insecurely In org.apache.spark:spark-core
Description
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 2.3.1 | ||
maven | 2.1.3, 2.2.2 | ||
maven | 2.1.3, 2.2.2, 2.3.1 | ||
pypi | 2.2.2, 2.1.3 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.