CVE-2020-9480 | Apache SparkÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-06-240x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-9480 |
ʱ ¼ä |
2020-06-24 |
|
Àà ÐÍ |
RCE |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Apache Spark < = 2.4.5 |
0x01 ·ì϶ÏêÇé
Apache Spark ÊÇרΪ´ó¹æÄ£Êý¾Ý´¦ÖöøÉè¼ÆµÄ¼±¾çͨÓõÄÍÆËãÒýÇæ¡£SparkÊÇUC Berkeley AMP labËù¿ªÔ´µÄÀàHadoop MapReduceµÄͨÓò¢Ðпò¼Ü£¬ËüÓë Hadoop ÓµÓÐÀàËÆµÄ¿ªÔ´¼¯ÈºÍÆËã»·¾³£¬µ«ÊÇÁ½ÕßÖ®¼ä»¹´æÔÚһЩ·ÖÆçÖ®´¦£¬Õâʹ Spark ÔÚijЩ¹¤×÷¸ºÔØ·½Ãæ²û·¢µÃÔ½·¢Óźñ£¬Spark ÆôÓÃÁËÄÚ´æÉ¢²¼Êý¾Ý¼¯£¬³ýÁË¿ÉÄÜÌṩ½»»¥Ê½²éÎÊ±í£¬Ëü»¹Äܹ»ÓÅ»¯µü´ú¹¤×÷¸ºÔØ¡£
½üÈÕ£¬Apache¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öApache SparkÔ¶³Ì´úÂëÖ´Ðзì϶¡£ÔÚApache Spark 2.4.5ÒÔ¼°¸üÔç°æ±¾ÖУ¬¶ÀÁ¢×ÊÔ´ÖÎÀíÆ÷µÄÖ÷·þÎñÆ÷¿ÉÄܱ»ÅäÖÃΪ±ØÒªÍ¨¹ý¹²ÏíÃÜÔ¿½øÐÐÉí·ÝÑéÖ¤(spark.authenticate)¡£ÓÉÓÚSparkµÄÈÏÖ¤»úÔì´æÔÚȱµã£¬µ¼Ö¹²ÏíÃÜÔ¿ÈÏ֤ʧЧ¡£¹¥»÷Õß¿ÉÔÚδÊÚȨµÄÇé¿öÏ£¬Ô¶³Ì·¢Ë;«ÐÄ»ú¹ØµÄ¹ý³ÌŲÓÃÖ¸ÁÀ´Æô¶¯Spark¼¯ÈºÉϵÄÀûÓ÷¨Ê½×ÊÔ´£¬²¢»ñµÃÖ¸±ê·þÎñÆ÷µÄȨÏÞ£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£
¸Ã·ì϶µÈ¼¶Îª¸ßΣ£¬GA»Æ½ð¼×VSRC½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶ÖÁ×îа汾¡£
0x02 ´ëÖý¨Òé
¹Ù·½ÒѰ䲼×îа汾£¬ÏÂÔØµØÖ·£º
https://github.com/apache/spark/releases
0x03 ÓйØÐÂÎÅ
https://osint.geekcq.com/2020/06/23/cve-2020-9480/
0x04 ²Î¿¼Á´½Ó
https://spark.apache.org/security.html
0x05 ¹¦·òÏß
2020-06-24 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ