VDB
CVE-2020-9480
CVE-2020-9480
PUBLISHED
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).
EPSS 88.27% · 99.5th percentile
Risk Scores
EPSS Score
88.27%
99.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | spark | 0 |
| Bitnami | spark | 0 |
Timeline
- Jan 21, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
- Jun 23, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 10, 2021 CrowdSec Sighting
- Jun 15, 2021 EPSS Score
- Oct 21, 2021 CrowdSec Sighting
- Jan 6, 2022 EPSS Score
- Jan 28, 2022 PoC Published
References
- https://lists.apache.org/thread.html/r03ad9fe7c07d6039fba9f2152d345274473cb0af3d8a4794a6645f4b%40%3Cuser.spark.apache.org%3E url
- https://lists.apache.org/thread.html/ra0e62a18ad080c4ce6df5e0202a27eaada75222761efc3f7238b5a3b%40%3Ccommits.doris.apache.org%3E url
- https://lists.apache.org/thread.html/rb3956440747e41940d552d377d50b144b60085e7ff727adb0e575d8d%40%3Ccommits.submarine.apache.org%3E url
- https://lists.apache.org/thread.html/ree9e87aae81852330290a478692e36ea6db47a52a694545c7d66e3e2%40%3Cdev.spark.apache.org%3E url
- https://spark.apache.org/security.html#CVE-2020-9480 url
- https://www.oracle.com/security-alerts/cpuApr2021.html url
- https://nvd.nist.gov/vuln/detail/CVE-2020-9480 url