apache-spark: RCE vulnerability in auth-enabled standalone master
Published Jun 23, 2020
9.3
CRITICALCVSS 4.0
EPSS 29.37%
Description
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).
Affected products
-
- Version Apache Spark 2.4.5 and earlierStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Spark | n/a |
|
Configuration 2
- 5.5.0.0.0
No data.
Red Hat Fuse 7
apache-spark
Not affected
Red Hat Integration Camel K 1
apache-spark
Not affected
Red Hat JBoss Data Grid 7
apache-spark
Not affected
Red Hat JBoss Fuse 6
apache-spark
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | apache-spark | Not affected | n/a |
| Red Hat Integration Camel K 1 | apache-spark | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | apache-spark | Not affected | n/a |
| Red Hat JBoss Fuse 6 | apache-spark | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- https://access.redhat.com/security/cve/CVE-2020-9480 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1887887 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0158 Advisory
- https://github.com/advisories/GHSA-wgx7-jwwm-cgjv Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2020-95.yaml
- https://lists.apache.org/thread.html/r03ad9fe7c07d6039fba9f2152d345274473cb0af3d8a4794a6645f4b%40%3Cuser.spark.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r03ad9fe7c07d6039fba9f2152d345274473cb0af3d8a4794a6645f4b@%3Cuser.spark.apache.org%3E
- https://lists.apache.org/thread.html/ra0e62a18ad080c4ce6df5e0202a27eaada75222761efc3f7238b5a3b%40%3Ccommits.doris.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ra0e62a18ad080c4ce6df5e0202a27eaada75222761efc3f7238b5a3b@%3Ccommits.doris.apache.org%3E
- https://lists.apache.org/thread.html/rb3956440747e41940d552d377d50b144b60085e7ff727adb0e575d8d%40%3Ccommits.submarine.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb3956440747e41940d552d377d50b144b60085e7ff727adb0e575d8d@%3Ccommits.submarine.apache.org%3E
- https://lists.apache.org/thread.html/ree9e87aae81852330290a478692e36ea6db47a52a694545c7d66e3e2%40%3Cdev.spark.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ree9e87aae81852330290a478692e36ea6db47a52a694545c7d66e3e2@%3Cdev.spark.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2020-9480
- https://spark.apache.org/security.html#CVE-2020-9480 x_refsource_CONFIRMVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-9480
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.