CVE-2019-10099: Apache Spark
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchToMem); in SparkR, using parallelize; in Pyspark, using broadcast and parallelize; and use of python udfs.
Affected products
- Apache Spark: from 1.0.2, up to and including 1.6.3; from 2.0.0, up to and including 2.0.2; from 2.1.0, up to and including 2.1.3; from 2.2.0, up to and including 2.2.2; from 2.3.0, before 2.3.2 (fixed in 2.3.2)
Published 2019-08-07. Last modified 2026-06-17.