Apache Spark XSS·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-13·ì϶±àºÅ
CVE-2018-8024
·ì϶¼¶±ð
³§ÉÌ×ÔÆÀ£ºÖÐΣ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ°æ±¾£º
Spark 2.1.2
Spark 2.2.0µ½2.2.1
Spark 2.3.0
·ì϶¸ÅÊö
Apache SparkÊÇ»ùÓÚÄÚ´æÍÆËãµÄ´óÊý¾Ý²¢ÐÐÍÆËã¿ò¼Ü£¬ÔÚ´óÊý¾Ý»·¾³ÖÐ¿í·ºÀûÓá£
ÔÚApache SparkÖУ¬Ô̺¬2.1.2,2.2.0µ½2.2.1ºÍ2.3.0£¬¶ñÒâÓû§Äܹ»¹¹½¨Ò»¸öÖ¸ÏòSpark¼¯ÈºUI×÷ÒµºÍ½×¶ÎÐÅÏ¢Ò³ÃæµÄURL£¬ÈôÊÇÓû§±»ºýŪ½Ó¼ûURL£¬¿É´ÓÓû§µÄSpark UIÊÓͼÖе¼Ö¾籾ִÐÐÒÔ¼°ÐÅϢй©¡£¹ÌȻһЩä¯ÀÀÆ÷£¨Èç×î½ü°æ±¾µÄChromeºÍSafari£©¿ÉÄÜ×èÖ¹´ËÀ๥»÷£¬µ«µ±Ç°°æ±¾µÄFirefox£¨¿ÉÄÜ»¹ÓÐÆäËû£©»¹ÊÜÓ°Ïì¡£
½¨¸´½¨Òé
Ŀǰ¹Ù·½Òѽ¨¸´¸Ã·ì϶£º
1.x, 2.0.x,ºÍ2.1.xÉý¼¶ÖÁ2.1.3¡£
2.2.xÉý¼¶ÖÁ2.2.2¡£
2.3.xÉý¼¶ÖÁ2.3.1¡£
²Î¿¼Á´½Ó
http://www.scap.org.cn/CVE-2018-8024.html
https://lists.apache.org/thread.html/5f241d2cda21cbcb3b63e46e474cf5f50cce66927f08399f4fab0aba@<dev.spark.apache.org>
https://spark.apache.org/security.html


¾©¹«Íø°²±¸11010802024551ºÅ