CVE-2020-9480 | Apache SparkÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-24

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-9480

ʱ    ¼ä

2020-06-24

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Apache Spark < = 2.4.5


0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Apache Spark ÊÇרΪ´ó¹æÄ£Êý¾Ý´¦ÖöøÉè¼ÆµÄ¼±¾çͨÓõÄÍÆËãÒýÇæ¡£¡£¡£¡£¡£¡£SparkÊÇUC Berkeley AMP labËù¿ªÔ´µÄÀàHadoop MapReduceµÄͨÓò¢Ðпò¼Ü£¬£¬£¬£¬£¬£¬£¬ËüÓë Hadoop ÓµÓÐÀàËÆµÄ¿ªÔ´¼¯ÈºÍÆËã»·¾³£¬£¬£¬£¬£¬£¬£¬µ«ÊÇÁ½ÕßÖ®¼ä»¹´æÔÚһЩ·ÖÆçÖ®´¦£¬£¬£¬£¬£¬£¬£¬Õâʹ Spark ÔÚijЩ¹¤×÷¸ºÔØ·½Ãæ²û·¢µÃÔ½·¢ÓÅÔ½£¬£¬£¬£¬£¬£¬£¬Spark ÆôÓÃÁËÄÚ´æÉ¢²¼Êý¾Ý¼¯£¬£¬£¬£¬£¬£¬£¬³ýÁË¿ÉÄÜÌṩ½»»¥Ê½²éÎÊ±í£¬£¬£¬£¬£¬£¬£¬Ëü»¹Äܹ»ÓÅ»¯µü´ú¹¤×÷¸ºÔØ¡£¡£¡£¡£¡£¡£

½üÈÕ£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½°ä²¼¹«¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËÒ»¸öApache SparkÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£ÔÚApache Spark 2.4.5ÒÔ¼°¸üÔç°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬¶ÀÁ¢×ÊÔ´ÖÎÀíÆ÷µÄÖ÷·þÎñÆ÷¿ÉÄܱ»ÅäÖÃΪ±ØÒªÍ¨¹ý¹²ÏíÃÜÔ¿½øÐÐÉí·ÝÑéÖ¤(spark.authenticate)¡£¡£¡£¡£¡£¡£ÓÉÓÚSparkµÄÈÏÖ¤»úÔì´æÔÚȱµã£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹²ÏíÃÜÔ¿ÈÏ֤ʧЧ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÔÚδÊÚȨµÄÇé¿öÏ£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì·¢Ë;«ÐÄ»ú¹ØµÄ¹ý³ÌŲÓÃÖ¸Á£¬£¬£¬£¬£¬£¬À´Æô¶¯Spark¼¯ÈºÉϵÄÀûÓ÷¨Ê½×ÊÔ´£¬£¬£¬£¬£¬£¬£¬²¢»ñµÃÖ¸±ê·þÎñÆ÷µÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£

¸Ã·ì϶µÈ¼¶Îª¸ßΣ£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅVSRC½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£¡£



0x02 ´ëÖý¨Òé


¹Ù·½ÒѰ䲼×îа汾£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµØÖ·£º

https://github.com/apache/spark/releases


0x03 ÓйØÐÂÎÅ


https://osint.geekcq.com/2020/06/23/cve-2020-9480/


0x04 ²Î¿¼Á´½Ó


https://spark.apache.org/security.html


0x05 ¹¦·òÏß


2020-06-24 VSRC°ä²¼·ì϶¹«¸æ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website