#VU15993 Improper input validation in Apache Spark - CVE-2018-17190
Published: November 20, 2018 / Updated: October 20, 2021
Apache Spark
Apache Foundation
Description
The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper security restrictions and insufficient validation of user-supplied input. An adjacent attacker with access to a Spark standalone cluster can send a specially crafted request that submits malicious input and execute arbitrary code on the master host, which could be used to conduct further attacks.