3.5.3
3 years ago
3 months ago
Known vulnerabilities in the org.apache.spark:spark-core_2.13 package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Command Injection due to the usage of Note:
CVE-2023-32007 was subsequently released to flag that How to fix Command Injection? Upgrade | [0,3.2.2) |
Affected versions of this package are vulnerable to Improper Privilege Management when applications using spark-submit can specify a Note: This vulnerability affects architectures relying on proxy-user, for example, those using Apache Livy to manage submitted applications. How to fix Improper Privilege Management? Upgrade | [,3.3.3) |
Affected versions of this package are vulnerable to Command Injection due to the usage of Note: CVE-2023-32007 was subsequently released to flag that How to fix Command Injection? Upgrade | [0,3.2.2) |