org.apache.spark:spark-core_2.12@2.4.8 vulnerabilities
-
latest version
3.5.3
-
latest non vulnerable version
-
first published
6 years ago
-
latest version published
2 months ago
-
licenses detected
- [2.4.0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.apache.spark:spark-core_2.12 package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.apache.spark:spark-core_2.12 is an unified analytics engine for large-scale data processing. It provides high-level APIs in Scala, Java, Python, and R, and an optimized engine that supports general computation graphs for data analysis. It also supports a rich set of higher-level tools including Spark SQL for SQL and DataFrames, pandas API on Spark for pandas workloads, MLlib for machine learning, GraphX for graph processing, and Structured Streaming for stream processing. Affected versions of this package are vulnerable to Command Injection due to the usage of Note:
CVE-2023-32007 was subsequently released to flag that How to fix Command Injection? Upgrade |
[0,3.2.2)
|
org.apache.spark:spark-core_2.12 is an unified analytics engine for large-scale data processing. It provides high-level APIs in Scala, Java, Python, and R, and an optimized engine that supports general computation graphs for data analysis. It also supports a rich set of higher-level tools including Spark SQL for SQL and DataFrames, pandas API on Spark for pandas workloads, MLlib for machine learning, GraphX for graph processing, and Structured Streaming for stream processing. Affected versions of this package are vulnerable to Improper Privilege Management when applications using spark-submit can specify a Note: This vulnerability affects architectures relying on proxy-user, for example, those using Apache Livy to manage submitted applications. How to fix Improper Privilege Management? Upgrade |
[,3.3.3)
|
org.apache.spark:spark-core_2.12 is an unified analytics engine for large-scale data processing. It provides high-level APIs in Scala, Java, Python, and R, and an optimized engine that supports general computation graphs for data analysis. It also supports a rich set of higher-level tools including Spark SQL for SQL and DataFrames, pandas API on Spark for pandas workloads, MLlib for machine learning, GraphX for graph processing, and Structured Streaming for stream processing. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade |
[,3.2.2)
[3.3.0,3.3.1)
|
org.apache.spark:spark-core_2.12 is an unified analytics engine for large-scale data processing. It provides high-level APIs in Scala, Java, Python, and R, and an optimized engine that supports general computation graphs for data analysis. It also supports a rich set of higher-level tools including Spark SQL for SQL and DataFrames, pandas API on Spark for pandas workloads, MLlib for machine learning, GraphX for graph processing, and Structured Streaming for stream processing. Affected versions of this package are vulnerable to Command Injection due to the usage of Note: CVE-2023-32007 was subsequently released to flag that How to fix Command Injection? Upgrade |
[0,3.2.2)
|
org.apache.spark:spark-core_2.12 is an unified analytics engine for large-scale data processing. It provides high-level APIs in Scala, Java, Python, and R, and an optimized engine that supports general computation graphs for data analysis. It also supports a rich set of higher-level tools including Spark SQL for SQL and DataFrames, pandas API on Spark for pandas workloads, MLlib for machine learning, GraphX for graph processing, and Structured Streaming for stream processing. Affected versions of this package are vulnerable to Arbitrary Command Execution via the How to fix Arbitrary Command Execution? Upgrade |
[,3.1.3)
[3.2.0,3.2.2)
|