Description
Apache Spark is an open-source distributed general-purpose cluster-computing framework.
Spark Web UI is designed to be accessed by trusted clients inside trusted environments. It's not recommended to have Apache Spark's services publicly accessible.
Remediation
It's recommended to restrict access to Apache Spark Web UI
References
Related Vulnerabilities
Unrestricted access to Prometheus
ZenCart Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4322)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.20)
Invalid Content Security Policy (CSP) Directive Identified in meta Elements
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1864)