Information Exposure Affecting spark-on-k8s package, versions [,0.7.0)
Threat Intelligence
Exploit Maturity
Proof of concept
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-SPARKONK8S-7361791
- published 24 Jun 2024
- disclosed 1 Jun 2024
- credit Hussein Awala
How to fix?
Upgrade spark-on-k8s
to version 0.7.0 or higher.
Overview
spark-on-k8s is an A Python package to submit and manage Apache Spark applications on Kubernetes.
Affected versions of this package are vulnerable to Information Exposure via the API query processing using a unique UUID, when an exception message is returned in case of an error.