Improper authorization control for web services In pyspark
Description
Pyspark User Impersonation Vulnerability When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.3.2, 2.2.3 | ||
maven | 2.3.2 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6.