Information Exposure Affecting org.apache.spark:spark-core_2.10 package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.4% (75th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHESPARK-72493
  • published26 Oct 2018
  • disclosed24 Oct 2018
  • creditAndre Protas

Introduced: 24 Oct 2018

CVE-2018-11804  (opens in a new tab)
CWE-200  (opens in a new tab)

Overview

org.apache.spark:spark-core_2.10 is a cluster computing system for Big Data.

Affected versions of this package are vulnerable to Information Exposure. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build.

Note This vulnerability only affects developers building Spark from source code, and does not affect Spark end users.

CVSS Scores

version 3.1