📦 Spark

by Apache

🔍 What is Spark?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-32007

HIGH CVSS 8.8 May 2, 2023

This vulnerability allows authenticated users to impersonate arbitrary users in Apache Spark UI when ACLs are enabled, leading to arbitrary shell command execution as the Spark service account. It aff...

CVE-2021-38296

HIGH CVSS 7.5 Mar 10, 2022

This vulnerability in Apache Spark allows attackers to recover full encryption keys from RPC connections using a flawed mutual authentication protocol. After an initial interactive attack, attackers c...

CVE-2025-55039

MEDIUM CVSS 6.5 Oct 15, 2025

Apache Spark versions before 3.4.4, 3.5.2, and 4.0.0 use an insecure default cipher (AES/CTR/NoPadding) for RPC encryption when spark.network.crypto.enabled is true, allowing man-in-the-middle attacke...

CVE-2024-23945

MEDIUM CVSS 5.9 Dec 23, 2024

Apache Hive and Spark expose correct cookie signatures during signature mismatch errors, potentially allowing attackers to forge valid signed cookies. This affects systems using Hive service or Spark ...