CVE-2020-27223
- EPSS 77.95%
- Veröffentlicht 26.02.2021 22:15:19
- Zuletzt bearbeitet 20.08.2025 10:15:27
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) ...
CVE-2020-27218
- EPSS 8.11%
- Veröffentlicht 28.11.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:20:52
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if a...
CVE-2020-9480
- EPSS 29.37%
- Veröffentlicht 23.06.2020 22:15:14
- Zuletzt bearbeitet 21.11.2024 05:40:43
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an ap...
CVE-2019-20445
- EPSS 13.47%
- Veröffentlicht 29.01.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:38:30
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
CVE-2019-10172
- EPSS 17.04%
- Veröffentlicht 18.11.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:34
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
CVE-2019-10099
- EPSS 1.3%
- Veröffentlicht 07.08.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:24
Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchToMem); in S...
CVE-2018-11760
- EPSS 0.61%
- Veröffentlicht 04.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:58
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
CVE-2018-17190
- EPSS 8.72%
- Veröffentlicht 19.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:03
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A specially-crafted request to the mast...
CVE-2018-11804
- EPSS 5.7%
- Veröffentlicht 24.10.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:04
Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including master. This server will accept conn...
CVE-2018-11770
- EPSS 65.83%
- Veröffentlicht 13.08.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:59
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secre...