CVE-2018-11804
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/10/2018
Last modified:
10/06/2024
Description
Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including master. This server will accept connections from external hosts by default. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build. Note that this issue does not affect end users of Spark, only developers building Spark from source code.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* | 1.3.0 (including) | 2.2.3 (excluding) |
| cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* | 2.3.0 (including) | 2.3.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



