CVE-2020-9480 | Apache SparkÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-06-240x00 Îó²î¸ÅÊö
CVE ID |
CVE-2020-9480 |
ʱ ¼ä |
2020-06-24 |
Àà ÐÍ |
RCE |
µÈ ¼¶ |
¸ßΣ |
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
Apache Spark < = 2.4.5 |
0x01 Îó²îÏêÇé
Apache Spark ÊÇרΪ´ó¹æÄ£Êý¾Ý´¦Öóͷ£¶øÉè¼ÆµÄ¿ìËÙͨÓõÄÅÌËãÒýÇæ¡£¡£¡£¡£¡£SparkÊÇUC Berkeley AMP labËù¿ªÔ´µÄÀàHadoop MapReduceµÄͨÓò¢Ðпò¼Ü£¬£¬£¬£¬ËüÓë Hadoop ¾ßÓÐÏàËÆµÄ¿ªÔ´¼¯ÈºÅÌËãÇéÐΣ¬£¬£¬£¬¿ÉÊÇÁ½ÕßÖ®¼ä»¹±£´æÒ»Ð©²î±ðÖ®´¦£¬£¬£¬£¬Õâʹ Spark ÔÚijЩÊÂÇé¸ºÔØ·½ÃæÌåÏÖµÃÔ½·¢ÓÅÔ½£¬£¬£¬£¬Spark ÆôÓÃÁËÄÚ´æÂþÑÜÊý¾Ý¼¯£¬£¬£¬£¬³ýÁËÄܹ»Ìṩ½»»¥Ê½ÅÌÎÊÍ⣬£¬£¬£¬Ëü»¹¿ÉÒÔÓÅ»¯µü´úÊÂÇé¸ºÔØ¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache SparkÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£ÔÚApache Spark 2.4.5ÒÔ¼°¸üÔç°æ±¾ÖУ¬£¬£¬£¬×ÔÁ¦×ÊÔ´ÖÎÀíÆ÷µÄÖ÷ЧÀÍÆ÷¿ÉÄܱ»ÉèÖÃΪÐèҪͨ¹ý¹²ÏíÃÜÔ¿¾ÙÐÐÉí·ÝÑéÖ¤(spark.authenticate)¡£¡£¡£¡£¡£ÓÉÓÚSparkµÄÈÏÖ¤»úÖÆ±£´æÈ±ÏÝ£¬£¬£¬£¬µ¼Ö¹²ÏíÃÜÔ¿ÈÏ֤ʧЧ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÔÚδÊÚȨµÄÇéÐÎÏ£¬£¬£¬£¬Ô¶³Ì·¢ËÍÈ«ÐĽṹµÄÀú³ÌŲÓÃÖ¸Á£¬£¬£¬À´Æô¶¯Spark¼¯ÈºÉϵÄÓ¦ÓóÌÐò×ÊÔ´£¬£¬£¬£¬²¢»ñµÃÄ¿µÄЧÀÍÆ÷µÄȨÏÞ£¬£¬£¬£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
¸ÃÎó²îÆ·¼¶Îª¸ßΣ£¬£¬£¬£¬¼øºÚµ£±£ÍøVSRC½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
¹Ù·½ÒÑÐû²¼×îа汾£¬£¬£¬£¬ÏÂÔØµØµã£º
https://github.com/apache/spark/releases
0x03 Ïà¹ØÐÂÎÅ
https://osint.geekcq.com/2020/06/23/cve-2020-9480/
0x04 ²Î¿¼Á´½Ó
https://spark.apache.org/security.html
0x05 ʱ¼äÏß
2020-06-24 VSRCÐû²¼Îó²îͨ¸æ
