2.1 LOW
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Exploit Maturity (E): POC (P)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse dismissed
perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
References
-
VDB-383321 | perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink technical-descriptionvdb-entry
-
-
CVE-2026-17459 | CVE Analysis and Report third-party-advisory
-
Affected products
- ==2.9.3
- ==2.9.2
- ==2.9.0
- ==2.9.1
- ==2.9.4
Matching in nixpkgs
pkgs.spark
Apache Spark is a fast and general engine for large-scale data processing
pkgs.spark3
Apache Spark is a fast and general engine for large-scale data processing
pkgs.spark4
Apache Spark is a fast and general engine for large-scale data processing
pkgs.sparkle
Another Mihomo GUI
pkgs.spark_3_4
Apache Spark is a fast and general engine for large-scale data processing
pkgs.spark_3_5
Apache Spark is a fast and general engine for large-scale data processing
pkgs.spark_4_0
Apache Spark is a fast and general engine for large-scale data processing
pkgs.lightspark
Open source Flash Player implementation
pkgs.forge-sparks
Get Git forges notifications
pkgs.fishPlugins.spark
Sparklines for Fish
pkgs.python313Packages.pyspark
Python bindings for Apache Spark
pkgs.python314Packages.pyspark
Python bindings for Apache Spark
pkgs.haskellPackages.hsparklines
Sparklines for Haskell
pkgs.python313Packages.findspark
Find pyspark to make it importable
pkgs.python314Packages.findspark
Find pyspark to make it importable
pkgs.python313Packages.sparklines
This Python package implements Edward Tufte's concept of sparklines, but limited to text only
pkgs.python314Packages.sparklines
This Python package implements Edward Tufte's concept of sparklines, but limited to text only
pkgs.haskellPackages.hackage-sparks
Generate sparkline graphs of hackage statistics
pkgs.python313Packages.spark-parser
Early-Algorithm Context-free grammar Parser
pkgs.python314Packages.spark-parser
Early-Algorithm Context-free grammar Parser
pkgs.haskellPackages.cisco-spark-api
DEPRECATED in favor of webex-teams-api
pkgs.haskellPackages.amazonka-gamesparks
Amazon GameSparks SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-26.05 2.0-unstable-2025-04-16
- nixos-26.05-small 2.0-unstable-2025-04-16
- nixpkgs-26.05-darwin 2.0-unstable-2025-04-16
pkgs.python313Packages.azure-synapse-spark
Microsoft Azure Synapse Spark Client Library
pkgs.python314Packages.azure-synapse-spark
Microsoft Azure Synapse Spark Client Library
pkgs.python313Packages.types-aiobotocore-gamesparks
Type annotations for aiobotocore gamesparks
pkgs.python314Packages.types-aiobotocore-gamesparks
Type annotations for aiobotocore gamesparks
-
nixos-unstable -
- nixos-unstable-small 2.7.0
Package maintainers
-
@theobori Théo Bori <theobori@disroot.org>
-
@getchoo Seth Flynn <getchoo@tuta.io>
-
@michaelgrahamevans Michael Evans <michaelgrahamevans@gmail.com>
-
@Aleksanaa Aleksana QwQ <me@aleksana.moe>
-
@jchv John Chadwick <johnwchadwick@gmail.com>
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>
-
@shlevy Shea Levy <shea@shealevy.com>
-
@sarahec Sarah Clark <seclark@nextquestion.net>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@rhoriguchi Ryan Horiguchi <ryan.horiguchi@gmail.com>
-
@illustris Harikrishnan R <me@illustris.tech>
-
@thoughtpolice Austin Seipp <aseipp@pobox.com>
-
@kamilchm Kamil Chmielewski <kamil.chm@gmail.com>
-
@chillcicada chillcicada <2210227279@qq.com>