Improper input validation in Apache Spark - CVE-2018-17190

 

Improper input validation in Apache Spark - CVE-2018-17190

Published: November 20, 2018 / Updated: October 20, 2021


Vulnerability identifier: #VU15993
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17190
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper security restrictions and insufficient validation of user-supplied input. An adjacent attacker with access to a Spark standalone cluster can send a specially crafted request that submits malicious input and execute arbitrary code on the master host, which could be used to conduct further attacks.


Affected software

Apache Spark
Gentoo Linux
Cloudera Observability with IBM
QRadar User Behavior Analytics

How to mitigate CVE-2018-17190

Install update from vendor's website.

Cloudera Observability with IBM - update to 3.5.3
QRadar User Behavior Analytics - update to 4.1.16

External References

Related Security Bulletins