VDB

CVE-2018-8024

CVE-2018-8024 PUBLISHED CVSS 5.400000095367432 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark via crafted URL

EPSS 61.14% · 98.3th percentile

Risk Scores

CVSS v3.0
5.400000095367432
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
61.14%
98.3th percentile

Affected Products

VendorProductVersions
Mavenorg.apache.spark:spark-core_2.112.1.0, 2.3.0, 2.3.0
mozillafirefox
Apache Software FoundationApache Spark1.0.0 to 2.1.2, 2.2.0 to 2.2.1, 2.3.0
apachespark2.2.0, 2.1.0, 2.3.0
Mavenorg.apache.spark:spark-core_2.102.2.0, 2.1.0

Timeline

  • Jul 12, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Sep 14, 2022 CVE Updated
  • Mar 7, 2023 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 29, 2025 EPSS Score
  • Mar 30, 2025 EPSS Score
  • Apr 12, 2025 EPSS Score
  • Jun 5, 2025 PoC Published
  • Jun 6, 2025 EPSS Score
  • Jun 8, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›