DescriptionSpark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including master. This server will accept connections from external hosts by default. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build. Note that this issue does not affect end users of Spark, only developers building Spark from source code.
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
|National Vulnerability Database|
|National Vulnerability Database||SUSE|
Status of this issue by product and package
Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification. The updates are grouped by state of their lifecycle. SUSE product lifecycles are documented on the lifecycle page.
|Products under general support and receiving all security fixes.|
|SUSE Manager Server Module 4.2||spark-core||Analysis|
|Products past their end of life and not receiving proactive updates anymore.|
|HPE Helion OpenStack 8||spark||Not affected|
|SUSE Manager Server 3.0||spark||Not affected|
|SUSE Manager Server 3.1||spark||Not affected|
|SUSE Manager Server 3.2||spark-core||Not affected|
|SUSE OpenStack Cloud 8||spark||Not affected|
|SUSE OpenStack Cloud Crowbar 8||spark||Not affected|
SUSE Timeline for this CVECVE page created: Thu Oct 25 09:45:59 2018
CVE page last modified: Wed Feb 1 01:18:36 2023