Vulnerability identifier: #VU78721
Vulnerability risk: High
CVSSv3.1:
CVE-ID:
CWE-ID:
CWE-269
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Apache Spark
Server applications /
Frameworks for developing and running applications
Vendor:
Description
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper privilege management. A local user can send specially crafted configuration-related classes on the classpath and exploit this vulnerability to execute arbitrary code with the privileges of the submitting user.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
External links
http://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?