Skip to main content

Vendor/product archive

apache / spark CVEs

Beta · best-effort

22 CVEs tagged to apache / spark3 Critical, 8 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2025-54920

Published Mar 16, 2026

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55039

Published Oct 15, 2025

This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher f…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23945

Published Dec 23, 2024

Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious act…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32007

Published May 2, 2023

** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this check…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22946

Published Apr 17, 2023

In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privi…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31777

Published Nov 1, 2022

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a use…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33891

Published Jul 18, 2022

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access perm…

CVSS 8.8 · High
evidence mentions
4
Buzz score
55.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2020-9480

Published Jun 23, 2020

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, howev…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10099

Published Aug 7, 2019

Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11760

Published Feb 4, 2019

When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17190

Published Nov 19, 2018

In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11804

Published Oct 24, 2018

Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branche…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11770

Published Aug 13, 2018

From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8024

Published Jul 12, 2018

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1334

Published Jul 12, 2018

In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersona…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12612

Published Sep 13, 2017

In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmatically using the lau…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7678

Published Jul 12, 2017

In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark clu…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1