
Cloud Vulnerability DB
A community-led vulnerabilities database
In Apache Spark 2.4.5 and earlier, a critical security vulnerability (CVE-2020-9480) was identified in the standalone resource manager's master authentication system. The vulnerability was discovered and disclosed in June 2020, affecting Apache Spark's standalone cluster mode when authentication is enabled via spark.authenticate configuration (Apache Security).
The vulnerability exists in the authentication mechanism of Spark's standalone resource manager. When authentication is enabled using spark.authenticate configuration with a shared secret, a specially-crafted RPC to the master can bypass the authentication check and successfully start an application's resources on the Spark cluster without providing the required shared key (Apache Security).
If successfully exploited, this vulnerability allows an attacker to execute shell commands on the host machine running the Spark cluster. The impact is limited to standalone Spark clusters with authentication enabled, and does not affect Spark deployments using other resource managers such as YARN or Mesos (Apache Security).
The vulnerability is remotely exploitable through a specially-crafted RPC request to the Spark master. The attack can be executed without requiring the shared authentication key, making it particularly dangerous for clusters that rely solely on spark.authenticate for security (Apache Security).
Users should upgrade to Apache Spark version 2.4.6 or 3.0.0 or later to address this vulnerability. Additionally, it is recommended to restrict network access to cluster machines to trusted hosts only as an additional security measure (Apache Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."