CVE-2020-9480
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).
En Apache Spark versión 2.4.5 y versiones anteriores, el maestro de un administrador de recursos independiente puede ser configurado para requerir autenticación (spark.authenticate) por medio de un secreto compartido. Sin embargo, cuando está habilitado, una RPC especialmente diseñado para el maestro puede tener éxito al iniciar los recursos de una aplicación en el clúster Spark, incluso sin la clave compartida. Esto se puede aprovechar para ejecutar comandos de shell sobre la máquina host. Esto no afecta a los clústeres de Spark que usan otros administradores de recursos (YARN, Mesos, etc.)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-01 CVE Reserved
- 2020-06-23 CVE Published
- 2024-05-30 EPSS Updated
- 2024-07-25 First Exploit
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (7)
URL | Date | SRC |
---|---|---|
https://github.com/XiaoShaYu617/CVE-2020-9480 | 2024-07-25 |
URL | Date | SRC |
---|---|---|
https://www.oracle.com/security-alerts/cpuApr2021.html | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://spark.apache.org/security.html#CVE-2020-9480 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Spark Search vendor "Apache" for product "Spark" | <= 2.4.5 Search vendor "Apache" for product "Spark" and version " <= 2.4.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Intelligence Search vendor "Oracle" for product "Business Intelligence" | 5.5.0.0.0 Search vendor "Oracle" for product "Business Intelligence" and version "5.5.0.0.0" | enterprise |
Affected
|