Apache Spark 多个漏洞 CVE-2018-17190, CVE-2018-11804, CVE-2018-11770, CVE-2018-8024, CVE-2018-1334, CVE-2017-12612, CVE-2017-7678

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Reporting Security Issues Apache Spark uses the standard process outlined by the [Apache Security Team](https://www.apache.org/security/) for reporting vulnerabilities. Note that vulnerabilities should not be publicly disclosed until the project has responded. To report a possible security vulnerability, please email security@apache.org. This is a non-public list that will reach the Apache Security team, as well as the Spark PMC. ### Known Security Issues **CVE-2018-17190: Unsecured Apache Spark standalone executes user code** Severity: Low Vendor: The Apache Software Foundation Versions Affected: - All versions of Apache Spark Description: Spark’s standalone resource manager accepts code to execute on a ‘master’ host, that then runs that code on ‘worker’ hosts. The master itself does not, by design, execute user code. A specially-crafted request to the master can, however, cause the master to execute code too. Note that this does not affect standalone clusters with...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息