Description
Apache Spark is an open-source distributed general-purpose cluster-computing framework.
Spark Web UI is designed to be accessed by trusted clients inside trusted environments. It's not recommended to have Apache Spark's services publicly accessible.
Remediation
It's recommended to restrict access to Apache Spark Web UI
References
Related Vulnerabilities
Xdebug remote code execution via xdebug.remote_connect_back
Spring Boot Misconfiguration: H2 console enabled
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-0211)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-17671)