Apache Spark XSS·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-07-13

·ì϶±àºÅ

CVE-2018-8024 

 

·ì϶¼¶±ð

³§ÉÌ×ÔÆÀ£ºÖÐΣ  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

 

Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ°æ±¾£º

Spark 2.1.2

Spark 2.2.0µ½2.2.1

Spark 2.3.0

 

·ì϶¸ÅÊö

Apache SparkÊÇ»ùÓÚÄÚ´æÍÆËãµÄ´óÊý¾Ý²¢ÐÐÍÆËã¿ò¼Ü£¬ÔÚ´óÊý¾Ý»·¾³ÖÐ¿í·ºÀûÓá£

ÔÚApache SparkÖУ¬Ô̺¬2.1.2,2.2.0µ½2.2.1ºÍ2.3.0£¬¶ñÒâÓû§Äܹ»¹¹½¨Ò»¸öÖ¸ÏòSpark¼¯ÈºUI×÷ÒµºÍ½×¶ÎÐÅÏ¢Ò³ÃæµÄURL£¬ÈôÊÇÓû§±»ºýŪ½Ó¼ûURL£¬¿É´ÓÓû§µÄSpark UIÊÓͼÖе¼Ö¾籾ִÐÐÒÔ¼°ÐÅϢй©¡£¹ÌȻһЩä¯ÀÀÆ÷£¨Èç×î½ü°æ±¾µÄChromeºÍSafari£©¿ÉÄÜ×èÖ¹´ËÀ๥»÷£¬µ«µ±Ç°°æ±¾µÄFirefox£¨¿ÉÄÜ»¹ÓÐÆäËû£©»¹ÊÜÓ°Ïì¡£

 

½¨¸´½¨Òé

Ŀǰ¹Ù·½Òѽ¨¸´¸Ã·ì϶£º

1.x, 2.0.x,ºÍ2.1.xÉý¼¶ÖÁ2.1.3¡£ 

2.2.xÉý¼¶ÖÁ2.2.2¡£

2.3.xÉý¼¶ÖÁ2.3.1¡£

 

²Î¿¼Á´½Ó

http://www.scap.org.cn/CVE-2018-8024.html

https://lists.apache.org/thread.html/5f241d2cda21cbcb3b63e46e474cf5f50cce66927f08399f4fab0aba@<dev.spark.apache.org>

https://spark.apache.org/security.html