Apache Spark XSSÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-13

Îó²î±àºÅ

CVE-2018-8024 

 

Îó²î¼¶±ð

³§ÉÌ×ÔÆÀ£ºÖÐΣ  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

 

Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ°æ±¾£º

Spark 2.1.2

Spark 2.2.0µ½2.2.1

Spark 2.3.0

 

Îó²î¸ÅÊö

Apache SparkÊÇ»ùÓÚÄÚ´æÅÌËãµÄ´óÊý¾Ý²¢ÐÐÅÌËã¿ò¼Ü£¬£¬£¬£¬£¬£¬ÔÚ´óÊý¾ÝÇéÐÎÖÐÆÕ±éÓ¦Óᣡ£¡£

ÔÚApache SparkÖУ¬£¬£¬£¬£¬£¬°üÀ¨2.1.2,2.2.0µ½2.2.1ºÍ2.3.0£¬£¬£¬£¬£¬£¬¶ñÒâÓû§¿ÉÒÔ¹¹½¨Ò»¸öÖ¸ÏòSpark¼¯ÈºUI×÷ÒµºÍ½×¶ÎÐÅÏ¢Ò³ÃæµÄURL£¬£¬£¬£¬£¬£¬ÈôÊÇÓû§±»ÓÕÆ­»á¼ûURL£¬£¬£¬£¬£¬£¬¿É´ÓÓû§µÄSpark UIÊÓͼÖе¼Ö¾籾ִÐÐÒÔ¼°ÐÅÏ¢×ß©¡£¡£¡£ËäȻһЩä¯ÀÀÆ÷£¨Èç×î½ü°æ±¾µÄChromeºÍSafari£©Äܹ»×èÖ¹´ËÀ๥»÷£¬£¬£¬£¬£¬£¬µ«Ä¿½ñ°æ±¾µÄFirefox£¨¿ÉÄÜÉÐÓÐÆäËû£©»¹ÊÜÓ°Ïì¡£¡£¡£

 

ÐÞ¸´½¨Òé

ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´¸ÃÎó²î£º

1.x, 2.0.x,ºÍ2.1.xÉý¼¶ÖÁ2.1.3¡£¡£¡£ 

2.2.xÉý¼¶ÖÁ2.2.2¡£¡£¡£

2.3.xÉý¼¶ÖÁ2.3.1¡£¡£¡£

 

²Î¿¼Á´½Ó

http://www.scap.org.cn/CVE-2018-8024.html

https://lists.apache.org/thread.html/5f241d2cda21cbcb3b63e46e474cf5f50cce66927f08399f4fab0aba@<dev.spark.apache.org>

https://spark.apache.org/security.html