Home
CRITICAL: 10.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:ADefault status
unaffected
Any version before build 1122
affected
Description
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.
Problem types
CWE-807 Reliance on untrusted inputs in a security decision
CWE-290 Authentication bypass by spoofing
Product status
Any version before build 1122
References
www.remotespark.com/view/new.html