Information disclosure in Apache Spark - CVE-2018-11804

 

Information disclosure in Apache Spark - CVE-2018-11804

Published: October 25, 2018 / Updated: October 26, 2018


Vulnerability identifier: #VU15539
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11804
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.

The vulnerability exists due to improper security restrictions set on the build/mvn script. A remote attacker can send a specially crafted request that submits malicious input, download and run a zinc server to speed up compilation and access sensitive information in files readable to the developer account running the build.


Affected software

Apache Spark
QRadar User Behavior Analytics

How to mitigate CVE-2018-11804

Install update from vendor's website.

QRadar User Behavior Analytics - update to 4.1.16

External References

Related Security Bulletins