CVE-2018-11760: Medium severity apache spark vulnerability
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11760?
CVE-2018-11760 is a vulnerability related to PySpark that allows a different local user to connect to the Spark application and impersonate the user running the application.
Which versions of PySpark are affected by CVE-2018-11760?
PySpark versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1 are affected by CVE-2018-11760.
What is the severity of CVE-2018-11760?
CVE-2018-11760 has a severity rating of 5.5 (medium).
How can I fix CVE-2018-11760 in PySpark?
To fix CVE-2018-11760 in PySpark, update to version 2.2.3 or later for 2.2.x versions, and update to version 2.3.2 or later for 2.3.x versions.
Where can I find more information about CVE-2018-11760?
You can find more information about CVE-2018-11760 on the NIST National Vulnerability Database (NVD) website.