CVE-2019-10099
Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encr
Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchToMem)
in SparkR, using parallelize.
in Pyspark, using broadcast and parallelize.
and use of python udfs.
HIGH · CVSS 7.5
EPSS 0.00285
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0