Back

CRITICAL

apache-spark: RCE vulnerability in auth-enabled standalone master

Published Jun 23, 2020

Description

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

Affected products

Remediation

No remediation recorded yet.

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jun 23, 2020
Updated Aug 4, 2024
Reserved Mar 1, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 22, 2020
ENISA EUVD
Assigner apache
Published Jun 23, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-0158 GHSA-WGX7-JWWM-CGJV