{"id":"PYSEC-2018-25","details":"In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.","aliases":["CVE-2018-1334","GHSA-6mqq-8r44-vmjc"],"modified":"2023-11-08T03:59:53.568496Z","published":"2018-07-12T13:29:00Z","references":[{"type":"WEB","url":"https://spark.apache.org/security.html#CVE-2018-1334"},{"type":"WEB","url":"https://lists.apache.org/thread.html/4d6d210e319a501b740293daaeeeadb51927111fb8261a3e4cd60060@%3Cdev.spark.apache.org%3E"}],"affected":[{"package":{"name":"pyspark","ecosystem":"PyPI","purl":"pkg:pypi/pyspark"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.2"},{"introduced":"0"},{"fixed":"2.1.3"}]}],"versions":["2.1.1","2.1.2","2.2.0","2.2.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pyspark/PYSEC-2018-25.yaml"}}],"schema_version":"1.7.3"}