AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-17190

CRITICAL · CVSS 9.8 EPSS 8.72%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-11-19 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache.

CVE
CVE-2018-17190
Severity
CRITICAL
CVSS
9.8
EPSS
8.72%
Apache

Original NVD Description

In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A specially-crafted request to the master can, however, cause the master to execute code too. Note that this does not affect standalone clusters with authentication enabled. While the master host typically has less outbound access to other resources than a worker, the execution of code on the master is nevertheless unexpected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)