Vulnerability Description
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Spark | <= 2.4.5 |
| Oracle | Business Intelligence | 5.5.0.0.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r03ad9fe7c07d6039fba9f2152d345274473cb0af3d
- https://lists.apache.org/thread.html/ra0e62a18ad080c4ce6df5e0202a27eaada75222761
- https://lists.apache.org/thread.html/rb3956440747e41940d552d377d50b144b60085e7ff
- https://lists.apache.org/thread.html/ree9e87aae81852330290a478692e36ea6db47a52a6
- https://spark.apache.org/security.html#CVE-2020-9480Vendor Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatchThird Party Advisory
- https://lists.apache.org/thread.html/r03ad9fe7c07d6039fba9f2152d345274473cb0af3d
- https://lists.apache.org/thread.html/ra0e62a18ad080c4ce6df5e0202a27eaada75222761
- https://lists.apache.org/thread.html/rb3956440747e41940d552d377d50b144b60085e7ff
- https://lists.apache.org/thread.html/ree9e87aae81852330290a478692e36ea6db47a52a6
- https://spark.apache.org/security.html#CVE-2020-9480Vendor Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatchThird Party Advisory
FAQ
What is CVE-2020-9480?
CVE-2020-9480 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-craft...
How severe is CVE-2020-9480?
CVE-2020-9480 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-9480?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Spark, Oracle Business Intelligence.