← Vulnerability feed

Vulnerability record · CVE-2018-11770 · published 13 August 2018

CVE-2018-11770: Apache Spark standalone master REST API lacks authentication

Apache · Spark

From version 1.3.0 onward, the Apache Spark standalone master exposes a REST API for job submission that does not use the shared secret (spark.authenticate.secret) or any other authentication mechanism, and this gap is not adequately documented. An unauthenticated user can submit a driver program through that API, which matters because job submission is a privileged operation on a shared cluster.

4.2 CVSS 3.1 Medium EPSS 66% · top 0.8% CWE-287 · Improper authentication
4.2CVSS 3.1 base score, v2 4.9
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for authenticating requests to submit jobs via spark-submit. However, the REST API does not use this or any other authentication mechanism, and this is not adequately documented. In this case, a user would be able to run a driver program without authenticating, but not launch executors, using the REST API. This REST API is also used by Mesos, when set up to run in cluster mode (i.e., when also running MesosClusterDispatcher), for job submission. Future versions of Spark will improve documentation on these points, and prohibit setting 'spark.authenticate.secret' when running the REST APIs, to make this clear. Future versions will also disable the REST API by default in the standalone master by changing the default value of 'spark.master.rest.enabled' to 'false'.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityThe flaw allows unauthenticated driver submission but not executor launch, and CVSS rates it medium (4.2) despite a high EPSS score and an exploit-tagged advisory.

What it is

From version 1.3.0 onward, the Apache Spark standalone master exposes a REST API for job submission that does not use the shared secret (spark.authenticate.secret) or any other authentication mechanism, and this gap is not adequately documented. An unauthenticated user can submit a driver program through that API, which matters because job submission is a privileged operation on a shared cluster.

Impact

An attacker can run a driver program on the cluster without authenticating, consuming cluster resources and executing code under the cluster's context. The description states they cannot launch executors via this path, so the gain is limited to driver submission rather than full executor control.

Attack surface

Reached over the network via the Spark standalone master REST API (and the same API when used by Mesos in cluster mode with MesosClusterDispatcher). No authentication is required; the CVSS vector indicates network access with low privileges and no user interaction.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high (0.6583, 99.2nd percentile), and the vendor advisory reference is tagged Exploit, indicating public exploit information exists.

What to do

  • Upgrade to a Spark release that disables the standalone master REST API by default (spark.master.rest.enabled=false) and prohibits setting spark.authenticate.secret when REST APIs are enabled.
  • If upgrading is not immediate, set spark.master.rest.enabled to false on standalone masters and Mesos cluster dispatchers.
  • Restrict network access to the Spark master REST port to trusted hosts only.
  • Do not rely on spark.authenticate.secret to protect the REST API; it does not apply to it.
  • Review cluster job submission logs for unexpected driver submissions.

Detection

  • Monitor Spark master REST API endpoints for job submission requests from unexpected source hosts.
  • Alert on driver submissions that do not correlate with known spark-submit clients or authorized users.
  • Audit whether spark.master.rest.enabled is true on standalone masters and Mesos cluster dispatchers.
  • Review Spark master and dispatcher logs for anomalous driver creation events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11770 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-33891Apache Spark UI ACL impersonation leads to OS command injectionApache Spark's UI ACL feature (spark.acls.enable) contains a flaw in HttpSecurityFilter where a user can supply an arbitrary username to impersonate …KEVEPSS 93%analysed9.9CVE-2023-22946Apache spark improper privilege management vulnerabilityIn Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c…EPSS 1.1%9.8CVE-2020-9480Apache spark missing authentication for critical function vulnerabilityIn Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…EPSS 29%9.8CVE-2018-17190Apache spark vulnerabilityIn all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hos…EPSS 8.8%9.1CVE-2019-20445Netty http request smuggling vulnerabilityHttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-En…EPSS 13%8.8CVE-2025-54920Apache spark deserialization of untrusted data vulnerabilityThis issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.…EPSS 5.3%8.8CVE-2023-32007Apache Spark UI ACL impersonation leads to shell command injectionWhen spark.acls.enable is on, a code path in Apache Spark's HttpSecurityFilter lets a user impersonate an arbitrary username. That impersonated name …EPSS 76%analysed7.8CVE-2017-12612Apache spark deserialization of untrusted data vulnerabilityIn Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched …EPSS 0.73%

Source: NIST National Vulnerability Database (record CVE-2018-11770), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.