CVE-2018-8024

Source
https://cve.org/CVERecord?id=CVE-2018-8024
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8024.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-8024
Aliases
Related
Published
2018-07-12T13:29:00.273Z
Modified
2026-04-10T04:11:23.983741Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

References

Affected packages

Git / github.com/apache/spark

Affected ranges

Type
GIT
Repo
https://github.com/apache/spark
Events
Introduced
Last affected
Introduced
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "2.1.0"
        },
        {
            "last_affected": "2.1.2"
        },
        {
            "introduced": "2.2.0"
        },
        {
            "last_affected": "2.2.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.0"
        }
    ]
}

Affected versions

0.*
0.3-scala-2.8
alpha-0.*
alpha-0.2
v0.*
v0.6.0
v0.7.0
v2.*
v2.1.0
v2.1.1
v2.1.2
v2.1.2-rc1
v2.1.2-rc2
v2.1.2-rc3
v2.1.2-rc4
v2.2.0
v2.2.1
v2.2.1-rc1
v2.2.1-rc2
v2.3.0
v2.3.0-rc1
v2.3.0-rc2
v2.3.0-rc3
v2.3.0-rc4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8024.json"