CVE-2018-11760

MEDIUM

PySpark <2.3.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 36.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (2)
apache/spark 1.0.2 - 1.6.3
pypi/pyspark 2.3.0 - 2.3.2PyPI
Published Feb 04, 2019
Tracked Since Feb 18, 2026