Known vulnerabilities in Apache Foundation Apache Spark

Website: https://www.apache.org
Total Security Bulletins: 12

Security bulletins (12)

Secuity bulletin Severity Status Published
SB2025112447: Inadequate encryption strength in Apache Spark Medium
Patched
24.11.2025
SB2024122316: Information disclosure in Apache Spark Medium
Patched
23.12.2024
SB2022110151: Stored XSS in Apache Spark Medium
Patched
01.11.2022
SB2022071809: OS command injection in Apache Spark Medium
Patched Exploited
18.07.2022
SB2021121722: Remote code execution in Apache Spark (Apache Log4j component) Critical
Patched Exploited
17.12.2021
SB2020070609: Authentication bypass in Apache Spark Medium
Patched Public exploit
06.07.2020
SB2019081422: Information disclosure in Apache Spark Low
Patched
14.08.2019
SB2019013106: Privilege escalation in Apache Spark Low
Patched
31.01.2019
SB2018112114: Arbitrary code execution in Apache Spark Medium
Patched
21.11.2018
SB2018102602: Information disclosure in Apache Spark Low
Patched
26.10.2018
SB2018081606: Security restrictions bypass in Apache Spark Low
Patched Public exploit
16.08.2018
SB2018071407: Multiple vulnerabilities in Apache Spark Low
Patched Public exploit
14.07.2018