← Back to CVE List
Vulnerability Intelligence Report
Apache Spark Key Negotiation Vulnerability

CVE-2021-38296

Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:1.82%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-294 ↗CWE-294 Authentication Bypass by Capture-replay

Affected Products & Versions

Vendor Product Affected Versions
Apache Software Foundation Apache Spark up to and including version 3.1.2 <= 3.1.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.817%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2021-08-09T00:00:00
Published2022-03-10T08:20:12
Last Updated2024-08-04T01:37:16

LINK COPIED TO CLIPBOARD