Tracker / CVE-2018-8024
CVE-2018-8024
Medium 5.4
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.
Affected products and versions
| apache | spark |
|---|---|
| apache | spark · 2.1.0 → 2.1.2 |
| apache | spark · 2.2.0 → 2.2.1 |
| mozilla | firefox |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.