CVE-2018-11770 describes an authentication bypass vulnerability in Apache Spark versions 1.3.0 and later, specifically within its standalone master's REST API for job submission. This API, also used by Mesos in cluster mode, lacks authentication despite the existence of 'spark.authenticate.secret' for spark-submit. An attacker could exploit this to run driver programs without authentication, though not launch executors. The vulnerability has a CVSS score of 4.2 (MEDIUM) due to its network-based attack vector and low impact on confidentiality and integrity, but a high attack complexity. Despite its medium CVSS, its EPSS score is exceptionally high (0.8957), indicating a significant likelihood of exploitation, and a Metasploit module exists for unauthenticated command execution. There is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.0, < 2.4.0CPE matchmatch criteria | cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.