PYSEC-2018-25

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pyspark/PYSEC-2018-25.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2018-25
Aliases
Published
2018-07-12T13:29:00Z
Modified
2023-11-08T03:59:53.568496Z
Summary
[none]
Details

In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.

References

Affected packages

PyPI / pyspark

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.2.0
Fixed
2.2.2
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.3

Affected versions

2.*

2.1.1
2.1.2
2.2.0
2.2.1