Document new security vulnerability in Apache Spark#683
Document new security vulnerability in Apache Spark#683miqowhy wants to merge 3 commits intoapache:asf-sitefrom
Conversation
Added details about CVE-2025-55039 vulnerability in Apache Spark, including severity, affected versions, descriptions, mitigations, and credit.
|
Thanks for adding this! There's a build step you need to follow the for website changes to be visible. |
|
Thanks for the reply, I'll follow the build step. But in parallel I think we need to clarify the affected versions - I'll be reproducing the CVE to check, but is there any reason why newer versions are not affected by this vulnerability? Looking at the docs of the latest version it looks like the vulnerable default is still in place. Or am I missing something? |
|
So I think https://issues.apache.org/jira/browse/SPARK-47172 indicates that the new config option is recommended for the new versions which if you follow the guidance in security settings is secure. |
I've run the build step now, hope this is enough |
Added details about CVE-2025-55039 vulnerability in Apache Spark, including severity, affected versions, descriptions, mitigations, and credit.
Two remarks: