CVE-2018-8024
MediumAdvisory
Published 14 Mar 2019In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.4
- base score, highest
- EPSS
- 0.053
- 92nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 5
- of 17,781 indexed, latest versions
- Container images
- 5
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark via crafted URL
Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| spark-core_2.11maven | 2.2.0, 2.2.0-k8s-0.5.0, 2.3.0 | 2.2.2, 2.3.1 | 5 |
- OSV records
- GHSA-8cw6-5qvp-q3wj
Charts affected
5 by stars
Container images carrying it
5 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| 5200710/ | e34ab066d2ed | spark-core_2.11 | 2.3.1 | 1 |
| apacheignite/ | d7deab68b8fa | spark-core_2.11 | 2.3.1 | 1 |
| dbanda/ | 0ca125e68e53 | spark-core_2.11 | 2.2.2 | 1 |
| snappydatainc/ | fd4b2070466f | spark-core_2.11 | 2.2.2 | 1 |
| sslhep/ | 9e80af083079 | spark-core_2.11 | 2.3.1 | 1 |