CVE-2020-9480 | Apache SparkÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-06-24

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-9480

ʱ    ¼ä

2020-06-24

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Spark < = 2.4.5


0x01 Îó²îÏêÇé


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Apache Spark ÊÇרΪ´ó¹æÄ£Êý¾Ý´¦Öóͷ£¶øÉè¼ÆµÄ¿ìËÙͨÓõÄÅÌËãÒýÇæ¡£¡£SparkÊÇUC Berkeley AMP labËù¿ªÔ´µÄÀàHadoop MapReduceµÄͨÓò¢Ðпò¼Ü£¬£¬£¬£¬ £¬£¬ËüÓë Hadoop ¾ßÓÐÏàËÆµÄ¿ªÔ´¼¯ÈºÅÌËãÇéÐΣ¬£¬£¬£¬ £¬£¬¿ÉÊÇÁ½ÕßÖ®¼ä»¹±£´æÒ»Ð©²î±ðÖ®´¦£¬£¬£¬£¬ £¬£¬Õâʹ Spark ÔÚijЩÊÂÇé¸ºÔØ·½ÃæÌåÏÖµÃÔ½·¢ÓÅÔ½£¬£¬£¬£¬ £¬£¬Spark ÆôÓÃÁËÄÚ´æÂþÑÜÊý¾Ý¼¯£¬£¬£¬£¬ £¬£¬³ýÁËÄܹ»Ìṩ½»»¥Ê½ÅÌÎÊÍ⣬£¬£¬£¬ £¬£¬Ëü»¹¿ÉÒÔÓÅ»¯µü´úÊÂÇé¸ºÔØ¡£¡£

¿ËÈÕ£¬£¬£¬£¬ £¬£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬ £¬£¬ÐÞ¸´ÁËÒ»¸öApache SparkÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£ÔÚApache Spark 2.4.5ÒÔ¼°¸üÔç°æ±¾ÖУ¬£¬£¬£¬ £¬£¬×ÔÁ¦×ÊÔ´ÖÎÀíÆ÷µÄÖ÷ЧÀÍÆ÷¿ÉÄܱ»ÉèÖÃΪÐèҪͨ¹ý¹²ÏíÃÜÔ¿¾ÙÐÐÉí·ÝÑéÖ¤(spark.authenticate)¡£¡£ÓÉÓÚSparkµÄÈÏÖ¤»úÖÆ±£´æÈ±ÏÝ£¬£¬£¬£¬ £¬£¬µ¼Ö¹²ÏíÃÜÔ¿ÈÏ֤ʧЧ¡£¡£¹¥»÷Õß¿ÉÔÚδÊÚȨµÄÇéÐÎÏ£¬£¬£¬£¬ £¬£¬Ô¶³Ì·¢ËÍÈ«ÐĽṹµÄÀú³ÌŲÓÃÖ¸Á£¬£¬£¬ £¬£¬À´Æô¶¯Spark¼¯ÈºÉϵÄÓ¦ÓóÌÐò×ÊÔ´£¬£¬£¬£¬ £¬£¬²¢»ñµÃÄ¿µÄЧÀÍÆ÷µÄȨÏÞ£¬£¬£¬£¬ £¬£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£

¸ÃÎó²îÆ·¼¶Îª¸ßΣ£¬£¬£¬£¬ £¬£¬ÄϹ¬NGÓéÀÖVSRC½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶ÖÁ×îа汾¡£¡£



0x02 ´¦Öóͷ£½¨Òé


¹Ù·½ÒÑÐû²¼×îа汾£¬£¬£¬£¬ £¬£¬ÏÂÔØµØµã£º

https://github.com/apache/spark/releases


0x03 Ïà¹ØÐÂÎÅ


https://osint.geekcq.com/2020/06/23/cve-2020-9480/


0x04 ²Î¿¼Á´½Ó


https://spark.apache.org/security.html


0x05 ʱ¼äÏß


2020-06-24 VSRCÐû²¼Îó²îͨ¸æ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾