PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated Oct 1, 2025

Apache Spark - Authentication Bypass

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-9480
9.8
CVSS

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache Sparkby Apache Software Foundation
Apache Spark 2.4.5 and earlier
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Apache Spark - Authentication Bypass CVE-2020-9480 Scanner | S4E