Apache Spark XSSÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-13

Îó²î±àºÅ

CVE-2018-8024 

 

Îó²î¼¶±ð

³§ÉÌ×ÔÆÀ£ºÖÐΣ  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

 

Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ°æ±¾£º

Spark 2.1.2

Spark 2.2.0µ½2.2.1

Spark 2.3.0

 

Îó²î¸ÅÊö

Apache SparkÊÇ»ùÓÚÄÚ´æÅÌËãµÄ´óÊý¾Ý²¢ÐÐÅÌËã¿ò¼Ü£¬£¬£¬£¬ÔÚ´óÊý¾ÝÇéÐÎÖÐÆÕ±éÓ¦Óᣡ£¡£¡£¡£¡£¡£¡£

ÔÚApache SparkÖУ¬£¬£¬£¬°üÀ¨2.1.2,2.2.0µ½2.2.1ºÍ2.3.0£¬£¬£¬£¬¶ñÒâÓû§¿ÉÒÔ¹¹½¨Ò»¸öÖ¸ÏòSpark¼¯ÈºUI×÷ÒµºÍ½×¶ÎÐÅÏ¢Ò³ÃæµÄURL£¬£¬£¬£¬ÈôÊÇÓû§±»ÓÕÆ­»á¼ûURL£¬£¬£¬£¬¿É´ÓÓû§µÄSpark UIÊÓͼÖе¼Ö¾籾ִÐÐÒÔ¼°ÐÅÏ¢×ß©¡£¡£¡£¡£¡£¡£¡£¡£ËäȻһЩä¯ÀÀÆ÷£¨Èç×î½ü°æ±¾µÄChromeºÍSafari£©Äܹ»×èÖ¹´ËÀ๥»÷£¬£¬£¬£¬µ«Ä¿½ñ°æ±¾µÄFirefox£¨¿ÉÄÜÉÐÓÐÆäËû£©»¹ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£

 

ÐÞ¸´½¨Òé

ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´¸ÃÎó²î£º

1.x, 2.0.x,ºÍ2.1.xÉý¼¶ÖÁ2.1.3¡£¡£¡£¡£¡£¡£¡£¡£ 

2.2.xÉý¼¶ÖÁ2.2.2¡£¡£¡£¡£¡£¡£¡£¡£

2.3.xÉý¼¶ÖÁ2.3.1¡£¡£¡£¡£¡£¡£¡£¡£

 

²Î¿¼Á´½Ó

http://www.scap.org.cn/CVE-2018-8024.html

https://lists.apache.org/thread.html/5f241d2cda21cbcb3b63e46e474cf5f50cce66927f08399f4fab0aba@<dev.spark.apache.org>

https://spark.apache.org/security.html