GHSA-62g2-m955-v383 · Severity: high · Ecosystem: maven — Improper Input Validation in Apache Spark
Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including master. This server will accept connections from external hosts by default. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build. Note that this issue does not affect end users of Spark, only developers building Spark from source code.
Conclusion & alert: CVE-2018-11804 is rated High Risk (67.2/100): CVSS High severity, with high exploitation likelihood (EPSS 5.70%, 92th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +5.05% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.65% | 5.70% | +5.05% |
| 2 | 2026-05-10 | 0.72% | 0.65% | -0.07% |
| 3 | 2025-12-10 | — | 0.72% | — |
Full EPSS history (21 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-62g2-m955-v383 · Severity: high · Ecosystem: maven — Improper Input Validation in Apache Spark
| vendor | priority | summary | link |
|---|---|---|---|
suse
|
medium | CVE-2018-11804 severity moderate: SUSE including 2 source package names (spark, spark-core), 6 product×package rows across 6 product lines (HPE Helion OpenStack 8, SUSE Manager Server 3.0, … (6 product lines)): Known Not Affected 6. | https://www.suse.com/security/cve/CVE-2018-11804/ |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/105756 | Broken Link Third Party Advisory VDB Entry |
| https://lists.apache.org/thread.html/2b11aa4201e36f2ec8f728e722fe33758410f07784379cbefd0bda9d%40%3Cdev.spark.apache.org%3E | Mailing List Third Party Advisory |
| https://spark.apache.org/security.html#CVE-2018-11804 | Mitigation Vendor Advisory |