{eval=Array;=+count(Array);}
Severity: Important
Vendor: The Apache Software Foundation
Versions Affected:
Description:
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as.
Mitigation
Credit:
官方链接:https://spark.apache.org/security.html
1
回答0
回答0
回答1
回答0
回答0
回答0
回答0
回答0
回答0
回答