StackRadar

CVE-2018-1334

Medium

Advisory

Published 12 Jul 2018In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
6
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
2 of 2
affected packages

Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark

Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
spark-core_2.11maven2.0.0, 2.2.0, 2.2.0-k8s-0.5.0, 2.3.02.1.3, 2.2.2, 2.3.16
pysparkpypi2.2.02.2.21
OSV records
GHSA-6mqq-8r44-vmjc
Also known as
PYSEC-2018-25

Charts affected

6 by stars
ChartLatestAffected imagesRadar Score
sparkmicrosoft1.0.41 of 3See more

spark microsoft 1.0.4

1 of the 3 container images this version deploys carry CVE-2018-1334.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
pyspark@2.2.0
spark-core_2.11@2.2.0
2.2.2
2.2.2

Open the chart page →

13,738
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2018-1334.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
spark-core_2.11@2.3.0
2.3.1

Open the chart page →

7,166
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2018-1334.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
spark-core_2.11@2.3.0
2.3.1

Open the chart page →

7,335
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2018-1334.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
spark-core_2.11@2.0.0
2.1.3

Open the chart page →

8,198
ignitecloudnativeapp1.0.01 of 1See more

ignite cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2018-1334.

Container imageDigestPackageFixed in
apacheignite/ignite:2.7.0d7deab68b8fa
spark-core_2.11@2.3.0
2.3.1

Open the chart page →

7,891
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-1334.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
spark-core_2.11@2.2.0-k8s-0.5.0
2.2.2

Open the chart page →

5,639

Container images carrying it

6 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
spark-core_2.11@2.3.0
2.3.1
1
apacheignite/ignite:2.7.0d7deab68b8fa
spark-core_2.11@2.3.0
2.3.1
1
dbanda/livy:0.80ca125e68e53
pyspark@2.2.0
spark-core_2.11@2.2.0
2.2.2
2.2.2
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
spark-core_2.11@2.0.0
2.1.3
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
spark-core_2.11@2.2.0-k8s-0.5.0
2.2.2
1
sslhep/hive-metastore:3.1.39e80af083079
spark-core_2.11@2.3.0
2.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.