CVE-2018-11760: Apache Spark
Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
Affected products
- Apache Spark: from 1.0.2, up to and including 1.6.3; from 2.0.0, up to and including 2.0.2; from 2.1.0, up to and including 2.1.3; from 2.2.0, up to and including 2.2.2; from 2.3.0, up to and including 2.3.1
Published 2019-02-04. Last modified 2026-06-17.