- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-26-2023
04:06 PM
- last edited on
03-18-2025
09:46 AM
by
Advika
Here is the previous discussion.
I have the following questions.
- Does CVE-2020-13949 affect the data plane or not?
- Do you know from which version of Databricks runtime you begin to have the patch for this vulnerability? Or is it confirmed that the patch for this vulnerability is included in Databricks runtime 10.4 LTS?
Thanks.
- Labels:
-
Azure databricks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-28-2023 10:49 AM
@Jimin Hsieh :
CVE-2020-13949 is a vulnerability in the Apache Thrift library, which is used in the Databricks control plane to manage clusters and other resources. Therefore, it does not directly affect the data plane of Databricks clusters. However, as a security vulnerability in a component used by the control plane, it could potentially be used to compromise the security of the entire Databricks environment if left unpatched.
Databricks has released patches for this vulnerability and recommends that users update to a version that includes the patch. The patch is included in Databricks Runtime 7.3 and later versions. It is not clear whether the patch is included in Databricks Runtime 10.4 LTS specifically, as the LTS versions may have additional backported security fixes. I recommend reaching out to Databricks support to confirm the patch status for your specific use case.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-30-2023 10:58 PM
Hi @Jimin Hsieh
Hope everything is going great.
Just wanted to check in if you were able to resolve your issue. If yes, would you be happy to mark an answer as best so that other members can find the solution more quickly? If not, please tell us so we can help you.
Cheers!