This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to false by default), but spark.network.crypto.cipher is not explicitly configured, Spark defaults to AES in CTR mode (AES/CTR/NoPadding), which provides encryption without authentication. This vulnerability allows a man-in-the-middle attacker to modify encrypted RPC traffic undetected by flipping bits in ciphertext, potentially compromising heartbeat messages or application data and affecting the integrity of Spark workflows. To mitigate this issue, users should either configure spark.network.crypto.cipher to AES/GCM/NoPadding to enable authenticated encryption or enable SSL encryption by setting spark.ssl.enabled to true, which provides stronger transport security.
Update org.apache.spark:spark-network-common_2.12 to 3.4.4; org.apache.spark:spark-network-common_2.12 to 3.5.2; org.apache.spark:spark-network-common_2.13 to 3.5.2; org.apache.spark:spark-network-common_2.13 to 3.4.4; pyspark to 3.4.4; pyspark to 3.5.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Spark has Inadequate Encryption Strength affects org.apache.spark:spark-network-common_2.12 (maven), org.apache.spark:spark-network-common_2.12 (maven), org.apache.spark:spark-network-common_2.13 (maven), org.apache.spark:spark-network-common_2.13 (maven), pyspark (pip), pyspark (pip). Severity is low. This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to false by default), but spark.network.crypto.cipher is not explicitly configured, Spark defaults to AES in CTR mode (AES/CTR/NoPadding), which provides encryption without authentication. This vulnerability allows a man-in-the-middle attacker to modify encrypted RPC traffic undetected by flipping bits in ciphertext, potentially compromising heartbeat messages or application data and affecting the integrity of Spark workflows. To mitigate this issue, users should either configure spark.network.crypto.cipher to AES/GCM/NoPadding to enable authenticated encryption or enable SSL encryption by setting spark.ssl.enabled to true, which provides stronger transport security.
AI coding agents often install or upgrade packages automatically in maven and pip. A low vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to false by default), but spark.network.crypto.cipher is not explicitly configured, Spark defaults to AES in CTR mode (AES/CTR/NoPadding), which provides encryption without authentication. This vulnerability allows a man-in-the-middle attacker to modify encrypted RPC traffic undetected by flipping bits in ciphertext, potentially compromising heartbeat messages or application data and affecting the integrity of Spark workflows. To mitigate this issue, users should either configure spark.network.crypto.cipher to AES/GCM/NoPadding to enable authenticated encryption or enable SSL encryption by setting spark.ssl.enabled to true, which provides stronger transport security.
Update org.apache.spark:spark-network-common_2.12 to 3.4.4; org.apache.spark:spark-network-common_2.12 to 3.5.2; org.apache.spark:spark-network-common_2.13 to 3.5.2; org.apache.spark:spark-network-common_2.13 to 3.4.4; pyspark to 3.4.4; pyspark to 3.5.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Spark has Inadequate Encryption Strength affects org.apache.spark:spark-network-common_2.12 (maven), org.apache.spark:spark-network-common_2.12 (maven), org.apache.spark:spark-network-common_2.13 (maven), org.apache.spark:spark-network-common_2.13 (maven), pyspark (pip), pyspark (pip). Severity is low. This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to false by default), but spark.network.crypto.cipher is not explicitly configured, Spark defaults to AES in CTR mode (AES/CTR/NoPadding), which provides encryption without authentication. This vulnerability allows a man-in-the-middle attacker to modify encrypted RPC traffic undetected by flipping bits in ciphertext, potentially compromising heartbeat messages or application data and affecting the integrity of Spark workflows. To mitigate this issue, users should either configure spark.network.crypto.cipher to AES/GCM/NoPadding to enable authenticated encryption or enable SSL encryption by setting spark.ssl.enabled to true, which provides stronger transport security.
AI coding agents often install or upgrade packages automatically in maven and pip. A low vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.spark:spark-network-common_2.12maven | <3.4.4 | 3.4.4 |
| org.apache.spark:spark-network-common_2.12maven | >=3.5.0,<3.5.2 | 3.5.2 |
| org.apache.spark:spark-network-common_2.13maven | >=3.5.0,<3.5.2 | 3.5.2 |
| org.apache.spark:spark-network-common_2.13maven | <3.4.4 | 3.4.4 |
| pysparkpip | >=0,<3.4.4 | 3.4.4 |
| pysparkpip | >=3.5.0,<3.5.2 | 3.5.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.spark:spark-network-common_2.12maven | <3.4.4 | 3.4.4 |
| org.apache.spark:spark-network-common_2.12maven | >=3.5.0,<3.5.2 | 3.5.2 |
| org.apache.spark:spark-network-common_2.13maven | >=3.5.0,<3.5.2 | 3.5.2 |
| org.apache.spark:spark-network-common_2.13maven | <3.4.4 | 3.4.4 |
| pysparkpip | >=0,<3.4.4 | 3.4.4 |
| pysparkpip | >=3.5.0,<3.5.2 | 3.5.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard