CVE Database
/

CVE-2018-11804

Back to search

CVE-2018-11804

Published: Oct 24, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including master. This server will accept connections from external hosts by default. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build. Note that this issue does not affect end users of Spark, only developers building Spark from source code.

VendorProductVersions

Apache Software Foundation

Apache Spark

affected
1.3.0 - < 3.*

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now