org.apache.spark:spark-core_2.13@3.2.3 vulnerabilities

  • latest version

    3.5.3

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    3 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.spark:spark-core_2.13 package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Privilege Management

    Affected versions of this package are vulnerable to Improper Privilege Management when applications using spark-submit can specify a proxy-user to run with limiting privileges., which allows the application to execute code with the privileges of the submitting user. Exploiting this vulnerability is possible by providing malicious configuration-related classes on the classpath.

    Note: This vulnerability affects architectures relying on proxy-user, for example, those using Apache Livy to manage submitted applications.

    How to fix Improper Privilege Management?

    Upgrade org.apache.spark:spark-core_2.13 to version 3.3.3 or higher.

    [,3.3.3)