#VU15993 Improper input validation in Apache Spark - CVE-2018-17190

 

#VU15993 Improper input validation in Apache Spark - CVE-2018-17190

Published: November 20, 2018 / Updated: October 20, 2021


Vulnerability identifier: #VU15993
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-17190
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Apache Spark
Software vendor:
Apache Foundation

Description

The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper security restrictions and insufficient validation of user-supplied input. An adjacent attacker with access to a Spark standalone cluster can send a specially crafted request that submits malicious input and execute arbitrary code on the master host, which could be used to conduct further attacks.


Remediation

Install update from vendor's website.

External links