Apache Spark Unauthenticated Command Execution
Posted by deepcore on December 1, 2018 – 12:05 am
This Metasploit module exploits an unauthenticated command execution vulnerability in Apache Spark with standalone cluster mode through the REST API. It uses the function CreateSubmissionRequest to submit a malicious java class and triggers it.
Post a reply
You must be logged in to post a comment.