VulnerabilityModified
CVE-2018-9159
In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences.
MEDIUM 5.3EPSS 4.45%
Does this matter?
Lower severity and a low EPSS score (4.45%). Track it; it rarely justifies an emergency change on its own.
Description
In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 4.45% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- sparkjava/spark
- Source
- cve@mitre.org
References
- http://sparkjava.com/news#spark-272-releasedVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2020Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2405Third Party Advisory
- https://github.com/perwendel/spark/commit/030e9d00125cbd1ad759668f85488aba1019c668Patch, Third Party Advisory
- https://github.com/perwendel/spark/commit/a221a864db28eb736d36041df2fa6eb8839fc5cdPatch, Third Party Advisory
- https://github.com/perwendel/spark/commit/ce9e11517eca69e58ed4378d1e47a02bd06863ccPatch, Third Party Advisory
- https://github.com/perwendel/spark/issues/981Issue Tracking, Third Party Advisory
- http://sparkjava.com/news#spark-272-releasedVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2020Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2405Third Party Advisory
- https://github.com/perwendel/spark/commit/030e9d00125cbd1ad759668f85488aba1019c668Patch, Third Party Advisory
- https://github.com/perwendel/spark/commit/a221a864db28eb736d36041df2fa6eb8839fc5cdPatch, Third Party Advisory
- https://github.com/perwendel/spark/commit/ce9e11517eca69e58ed4378d1e47a02bd06863ccPatch, Third Party Advisory
- https://github.com/perwendel/spark/issues/981Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.