Apache Spark XSSÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-07-13Îó²î±àºÅ
CVE-2018-8024
Îó²î¼¶±ð
³§ÉÌ×ÔÆÀ£ºÖÐΣ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ°æ±¾£º
Spark 2.1.2
Spark 2.2.0µ½2.2.1
Spark 2.3.0
Îó²î¸ÅÊö
Apache SparkÊÇ»ùÓÚÄÚ´æÅÌËãµÄ´óÊý¾Ý²¢ÐÐÅÌËã¿ò¼Ü£¬£¬£¬£¬£¬£¬ÔÚ´óÊý¾ÝÇéÐÎÖÐÆÕ±éÓ¦Óᣡ£¡£
ÔÚApache SparkÖУ¬£¬£¬£¬£¬£¬°üÀ¨2.1.2,2.2.0µ½2.2.1ºÍ2.3.0£¬£¬£¬£¬£¬£¬¶ñÒâÓû§¿ÉÒÔ¹¹½¨Ò»¸öÖ¸ÏòSpark¼¯ÈºUI×÷ÒµºÍ½×¶ÎÐÅÏ¢Ò³ÃæµÄURL£¬£¬£¬£¬£¬£¬ÈôÊÇÓû§±»ÓÕÆ»á¼ûURL£¬£¬£¬£¬£¬£¬¿É´ÓÓû§µÄSpark UIÊÓͼÖе¼Ö¾籾ִÐÐÒÔ¼°ÐÅÏ¢×ß©¡£¡£¡£ËäȻһЩä¯ÀÀÆ÷£¨Èç×î½ü°æ±¾µÄChromeºÍSafari£©Äܹ»×èÖ¹´ËÀ๥»÷£¬£¬£¬£¬£¬£¬µ«Ä¿½ñ°æ±¾µÄFirefox£¨¿ÉÄÜÉÐÓÐÆäËû£©»¹ÊÜÓ°Ïì¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´¸ÃÎó²î£º
1.x, 2.0.x,ºÍ2.1.xÉý¼¶ÖÁ2.1.3¡£¡£¡£
2.2.xÉý¼¶ÖÁ2.2.2¡£¡£¡£
2.3.xÉý¼¶ÖÁ2.3.1¡£¡£¡£
²Î¿¼Á´½Ó
http://www.scap.org.cn/CVE-2018-8024.html
https://lists.apache.org/thread.html/5f241d2cda21cbcb3b63e46e474cf5f50cce66927f08399f4fab0aba@<dev.spark.apache.org>
https://spark.apache.org/security.html