OESA-2022-1591

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2022-1591
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2022-1591.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2022-1591
Upstream
Published
2022-03-26T11:03:39Z
Modified
2025-08-12T05:09:36.928919Z
Summary
spark security update
Details

Apache Spark achieves high performance for both batch and streaming data, using a state-of-the-art DAG scheduler, a query optimizer, and a physical execution engine.

Security Fix(es):

Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later(CVE-2021-38296)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / spark

Package

Name
spark
Purl
pkg:rpm/openEuler/spark&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.0-1.oe1

Ecosystem specific

{
    "src": [
        "spark-3.2.0-1.oe1.src.rpm"
    ],
    "x86_64": [
        "spark-3.2.0-1.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "spark-3.2.0-1.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / spark

Package

Name
spark
Purl
pkg:rpm/openEuler/spark&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.0-1.oe1

Ecosystem specific

{
    "src": [
        "spark-3.2.0-1.oe1.src.rpm"
    ],
    "x86_64": [
        "spark-3.2.0-1.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "spark-3.2.0-1.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / spark

Package

Name
spark
Purl
pkg:rpm/openEuler/spark&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.0-1.oe1

Ecosystem specific

{
    "src": [
        "spark-3.2.0-1.oe1.src.rpm"
    ],
    "x86_64": [
        "spark-3.2.0-1.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "spark-3.2.0-1.oe1.aarch64.rpm"
    ]
}