← Vulnerability feed

Vulnerability record · CVE-2021-38296 · published 10 March 2022

CVE-2021-38296: Apache spark authentication bypass by capture-replay vulnerability

Apache · Spark

Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later

7.5 CVSS 3.1 High EPSS 1.8% · top 21.8% CWE-294 · Authentication bypass by capture-replay
7.5CVSS 3.1 base score, v2 5.0
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-38296 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-1273Spring Data Commons property binder allows remote code executionSpring Data Commons fails to properly neutralize special elements in request parameters, allowing crafted input to be bound to object properties. Thi…KEVEPSS 97%analysed8.8CVE-2022-33891Apache Spark UI ACL impersonation leads to OS command injectionApache Spark's UI ACL feature (spark.acls.enable) contains a flaw in HttpSecurityFilter where a user can supply an arbitrary username to impersonate …KEVEPSS 93%analysed9.9CVE-2023-22946Apache spark improper privilege management vulnerabilityIn Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c…EPSS 1.1%9.8CVE-2022-22978Vmware spring security incorrect authorization vulnerabilityIn spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be b…EPSS 12%9.8CVE-2021-41303Apache Shiro with Spring Boot authentication bypass via crafted HTTP requestApache Shiro before 1.8.0, when used with Spring Boot, can be tricked by a specially crafted HTTP request into bypassing authentication. The flaw is …EPSS 77%analysed9.8CVE-2020-9480Apache spark missing authentication for critical function vulnerabilityIn Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…EPSS 29%9.8CVE-2018-17190Apache spark vulnerabilityIn all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hos…EPSS 8.8%9.1CVE-2019-20445Netty http request smuggling vulnerabilityHttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-En…EPSS 13%

Source: NIST National Vulnerability Database (record CVE-2021-38296), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.