CVE-2020-9480 | Apache SparkÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-24

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-9480

ʱ    ¼ä

2020-06-24

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Apache Spark < = 2.4.5


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Apache Spark ÊÇרΪ´ó¹æÄ£Êý¾Ý´¦ÖöøÉè¼ÆµÄ¼±¾çͨÓõÄÍÆËãÒýÇæ¡£SparkÊÇUC Berkeley AMP labËù¿ªÔ´µÄÀàHadoop MapReduceµÄͨÓò¢Ðпò¼Ü£¬ËüÓë Hadoop ÓµÓÐÀàËÆµÄ¿ªÔ´¼¯ÈºÍÆËã»·¾³£¬µ«ÊÇÁ½ÕßÖ®¼ä»¹´æÔÚһЩ·ÖÆçÖ®´¦£¬Õâʹ Spark ÔÚijЩ¹¤×÷¸ºÔØ·½Ãæ²û·¢µÃÔ½·¢Óźñ£¬Spark ÆôÓÃÁËÄÚ´æÉ¢²¼Êý¾Ý¼¯£¬³ýÁË¿ÉÄÜÌṩ½»»¥Ê½²éÎʱí£¬Ëü»¹Äܹ»ÓÅ»¯µü´ú¹¤×÷¸ºÔØ¡£

½üÈÕ£¬Apache¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öApache SparkÔ¶³Ì´úÂëÖ´Ðзì϶¡£ÔÚApache Spark 2.4.5ÒÔ¼°¸üÔç°æ±¾ÖУ¬¶ÀÁ¢×ÊÔ´ÖÎÀíÆ÷µÄÖ÷·þÎñÆ÷¿ÉÄܱ»ÅäÖÃΪ±ØÒªÍ¨¹ý¹²ÏíÃÜÔ¿½øÐÐÉí·ÝÑéÖ¤(spark.authenticate)¡£ÓÉÓÚSparkµÄÈÏÖ¤»úÔì´æÔÚȱµã£¬µ¼Ö¹²ÏíÃÜÔ¿ÈÏ֤ʧЧ¡£¹¥»÷Õß¿ÉÔÚδÊÚȨµÄÇé¿öÏ£¬Ô¶³Ì·¢Ë;«ÐÄ»ú¹ØµÄ¹ý³ÌŲÓÃÖ¸ÁÀ´Æô¶¯Spark¼¯ÈºÉϵÄÀûÓ÷¨Ê½×ÊÔ´£¬²¢»ñµÃÖ¸±ê·þÎñÆ÷µÄȨÏÞ£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£

¸Ã·ì϶µÈ¼¶Îª¸ßΣ£¬GA»Æ½ð¼×VSRC½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶ÖÁ×îа汾¡£



0x02 ´ëÖý¨Òé


¹Ù·½ÒѰ䲼×îа汾£¬ÏÂÔØµØÖ·£º

https://github.com/apache/spark/releases


0x03 ÓйØÐÂÎÅ


https://osint.geekcq.com/2020/06/23/cve-2020-9480/


0x04 ²Î¿¼Á´½Ó


https://spark.apache.org/security.html


0x05 ¹¦·òÏß


2020-06-24 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾