{"id":"GHSA-fvxv-9xxr-h7wj","summary":"Pyspark User Impersonation Vulnerability","details":"When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.","aliases":["CVE-2018-11760","PYSEC-2019-169"],"modified":"2024-12-04T05:31:59.907142Z","published":"2019-02-07T18:02:21Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:35:31Z","nvd_published_at":"2019-02-04T17:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-11760"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fvxv-9xxr-h7wj"},{"type":"WEB","url":"https://github.com/apache/spark"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2019-169.yaml"},{"type":"WEB","url":"https://lists.apache.org/thread.html/6d015e56b3a3da968f86e0b6acc69f17ecc16b499389e12d8255bf6e@%3Ccommits.spark.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/a86ee93d07b6f61b82b61a28049aed311f5cc9420d26cc95f1a9de7b@%3Cuser.spark.apache.org%3E"},{"type":"WEB","url":"https://web.archive.org/web/20200227091119/http://www.securityfocus.com/bid/106786"},{"type":"WEB","url":"https://web.archive.org/web/20200925111106/https://issues.apache.org/jira/browse/SPARK-26802"}],"affected":[{"package":{"name":"pyspark","ecosystem":"PyPI","purl":"pkg:pypi/pyspark"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.3.2"}]}],"versions":["2.3.0","2.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-fvxv-9xxr-h7wj/GHSA-fvxv-9xxr-h7wj.json"}},{"package":{"name":"pyspark","ecosystem":"PyPI","purl":"pkg:pypi/pyspark"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.2"},{"fixed":"2.2.3"}]}],"versions":["2.1.1","2.1.2","2.1.3","2.2.0","2.2.1","2.2.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-fvxv-9xxr-h7wj/GHSA-fvxv-9xxr-h7wj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}