VDB

CVE-2020-9480

CVE-2020-9480 PUBLISHED

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

EPSS 88.27% · 99.5th percentile

Risk Scores

EPSS Score
88.27%
99.5th percentile

Affected Products

VendorProductVersions
Bitnamispark0
Bitnamispark0

Timeline

  • Jan 21, 1970 CrowdSec Sighting
  • Jan 21, 1970 CrowdSec Sighting
  • Jan 21, 1970 CrowdSec Sighting
  • Jan 21, 1970 CrowdSec Sighting
  • Jan 21, 1970 CrowdSec Sighting
  • Jun 23, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 10, 2021 CrowdSec Sighting
  • Jun 15, 2021 EPSS Score
  • Oct 21, 2021 CrowdSec Sighting
  • Jan 6, 2022 EPSS Score
  • Jan 28, 2022 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›