Vulnerability Intelligence Report
Apache Spark Key Negotiation Vulnerability
CVE-2021-38296
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:1.82%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-294 ↗CWE-294 Authentication Bypass by Capture-replay
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Apache Software Foundation | Apache Spark | up to and including version 3.1.2 <= 3.1.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.817%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Apache Software Foundation · Vendor · USA |
| Reserved | 2021-08-09T00:00:00 |
| Published | 2022-03-10T08:20:12 |
| Last Updated | 2024-08-04T01:37:16 |
Community Chatter & Buzz