Pyspark User Impersonation Vulnerability
Moderate severity
GitHub Reviewed
Published
Feb 7, 2019
to the GitHub Advisory Database
•
Updated Oct 24, 2024
Package
Affected versions
>= 2.3.0, < 2.3.2
>= 1.0.2, < 2.2.3
Patched versions
2.3.2
2.2.3
Description
Published by the National Vulnerability Database
Feb 4, 2019
Published to the GitHub Advisory Database
Feb 7, 2019
Reviewed
Jun 16, 2020
Last updated
Oct 24, 2024
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
References