Apache / Spark
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-32773 | Apache Spark: XSS Vulnerability in Spark Web 3.5.4 | MEDIUM | 6.1 | Sep 2, 2026 |
| CVE-2025-54920 | Apache Spark: Spark History Server Code Execution Vulnerability | HIGH | 8.8 | Mar 14, 2026 |
| CVE-2025-55039 | Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks | LOW | 2.9 | Oct 15, 2025 |
| CVE-2024-23945 | Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails | HIGH | 8.7 | Dec 23, 2024 |
| CVE-2023-32007 | Apache Spark: Shell command injection via Spark UI | HIGH | 8.7 | May 2, 2023 |
| CVE-2023-22946 | Apache Spark proxy-user privilege escalation from malicious configuration class | CRITICAL | 9.9 | Apr 17, 2023 |
| CVE-2022-31777 | Apache Spark XSS vulnerability in log viewer UI Javascript | MEDIUM | 5.4 | Nov 1, 2022 |
| CVE-2022-33891 KEV | Apache Spark shell command injection vulnerability via Spark UI | HIGH | 8.7 | Jul 18, 2022 |
| CVE-2021-38296 | Apache Spark Key Negotiation Vulnerability | HIGH | 8.7 | Mar 10, 2022 |
| CVE-2020-27223 | jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS | MEDIUM | 5.3 | Feb 26, 2021 |
| CVE-2020-27218 | jetty: buffer not correctly recycled in Gzip Request inflation | MEDIUM | 4.8 | Nov 28, 2020 |
| CVE-2020-9480 | apache-spark: RCE vulnerability in auth-enabled standalone master | CRITICAL | 9.3 | Jun 23, 2020 |
| CVE-2019-20445 | netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header | CRITICAL | 9.1 | Jan 29, 2020 |
| CVE-2019-10172 | jackson-mapper-asl: XML external entity similar to CVE-2016-3720 | HIGH | 7.5 | Nov 18, 2019 |
| CVE-2019-10099 | Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cach… | HIGH | 8.7 | Aug 7, 2019 |
| CVE-2018-11760 | spark: local priviledge escalation when using PySpark | MEDIUM | 6.8 | Feb 4, 2019 |
| CVE-2018-17190 | In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The ma… | CRITICAL | 9.8 | Nov 19, 2018 |
| CVE-2018-11804 | Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been include… | HIGH | 7.5 | Oct 24, 2018 |
| CVE-2018-11770 | spark: Missing authentication allows users to run driver programs via the REST API | MEDIUM | 4.2 | Aug 13, 2018 |
| CVE-2018-8024 | In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and sta… | MEDIUM | 5.4 | Jul 12, 2018 |
| CVE-2018-1334 | In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark appli… | MEDIUM | 6.0 | Jul 12, 2018 |
| CVE-2017-12612 | In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmat… | HIGH | 8.5 | Sep 13, 2017 |
| CVE-2017-7678 | In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points t… | MEDIUM | 6.1 | Jul 12, 2017 |
Showing 1 to 23 of 23 CVEs