module
Apache Spark Unauthenticated Command Execution
| Disclosed |
|---|
| Dec 12, 2017 |
Disclosed
Dec 12, 2017
Description
This module exploits an unauthenticated command execution vulnerability in Apache Spark with standalone cluster mode through REST API.
It uses the function CreateSubmissionRequest to submit a malious java class and trigger it.
It uses the function CreateSubmissionRequest to submit a malious java class and trigger it.
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.