Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-8024

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.326
EPSS Ranking 96.6%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 4.9
Products affected by CVE-2018-8024
  • Apache » Spark » Version: 2.1.0
    cpe:2.3:a:apache:spark:2.1.0
  • Apache » Spark » Version: 2.1.1
    cpe:2.3:a:apache:spark:2.1.1
  • Apache » Spark » Version: 2.1.2
    cpe:2.3:a:apache:spark:2.1.2
  • Apache » Spark » Version: 2.2.0
    cpe:2.3:a:apache:spark:2.2.0
  • Apache » Spark » Version: 2.2.1
    cpe:2.3:a:apache:spark:2.2.1
  • Apache » Spark » Version: 2.3.0
    cpe:2.3:a:apache:spark:2.3.0
  • Mozilla » Firefox » Version: N/A
    cpe:2.3:a:mozilla:firefox:-


Contact Us

Shodan ® - All rights reserved