References https://xxhzx.web.hebust.edu.cn/wlaq/934dc3f0d397424996692a1d66c8f4a3.htm https://x.threatbook.com/v5/article?threatInfoID=147917 http://www.nic.bjchyedu.cn/xxaq/aqtg/202411/t20241120_106132.html https://www.bessystem.com/partinfo/103107/info?p=103 https://stack.chaitin.com/vuldb/detail/c5f43310-a83f-41aa-8f86-fbc7b8e3c4e8 https://www.secevery.com/toBugInfo?id=1858411046027182081 https://cn-sec.com/archives/3404664.html
Related Vulnerabilities宝兰德BES中间件spark接口存在远程代码执行漏洞PoCremote-spark-gateway-config: Remote Spark Gateway Configuration/Credentials - ExposurePoCapache-spark-env: Apache Spark Environment - ExposurePoCCVE-2018-8024: Apache Spark UI - Cross-Site ScriptingPoCCVE-2022-33891: Apache Spark UI - Remote Command InjectionPoCCVE-2023-32007: Apache Spark远程代码执行漏洞PoCspark-api-unauth: spark Api UnauthPoCspark-webui-unauth: Spark WebUI UnauthenticatedPoCCVE-2020-9480: Apache Spark - Authentication BypassPoCapachespark-ui-exposed: Apache Spark Application UI - ExposedPoCspark-webui-unauth: Unauthenticated Spark WebUIPoCunauth-spark-api: Unauthenticated Spark REST API