Improper input validation in Apache Spark - CVE-2018-17190
Published: November 20, 2018 / Updated: October 20, 2021
Vulnerability details
The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper security restrictions and insufficient validation of user-supplied input. An adjacent attacker with access to a Spark standalone cluster can send a specially crafted request that submits malicious input and execute arbitrary code on the master host, which could be used to conduct further attacks.
Affected software
Gentoo Linux
Cloudera Observability with IBM
QRadar User Behavior Analytics
How to mitigate CVE-2018-17190
QRadar User Behavior Analytics - update to 4.1.16