← Back

CVE-2019-10099

nvd nist
Published: Aug 7, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchToMem); in SparkR, using parallelize; in Pyspark, using broadcast and parallelize; and use of python udfs.

Affected (5)

Products: Apache: Spark
1 product
Spark
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.0.2 to 1.6.3
From 2.0.0 to 2.0.2
From 2.1.0 to 2.1.3
From 2.2.0 to 2.2.2
From 2.3.0 to 2.3.2

Timeline

No history available yet.