GHSA-62g2-m955-v383

Suggest an improvement
Source
https://github.com/advisories/GHSA-62g2-m955-v383
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-62g2-m955-v383/GHSA-62g2-m955-v383.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-62g2-m955-v383
Aliases
Published
2022-05-14T01:50:10Z
Modified
2024-06-10T21:42:29Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Improper Input Validation in Apache Spark
Details

Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including master. This server will accept connections from external hosts by default. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build. Note that this issue does not affect end users of Spark, only developers building Spark from source code.

Database specific
{
    "nvd_published_at": "2018-10-24T18:29:00Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-06-29T23:07:22Z"
}
References

Affected packages

Maven / org.apache.spark:spark-core

Package

Name
org.apache.spark:spark-core
View open source insights on deps.dev
Purl
pkg:maven/org.apache.spark/spark-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.3.0
Last affected
2.1.3