Anonymous
Not applicable

@Jimin Hsieh​ :

CVE-2020-13949 is a vulnerability in Apache Tomcat, which is used by Databricks for web access to the control plane. This vulnerability can allow a remote attacker to view sensitive information, modify user sessions, or execute arbitrary code on the control plane. It does not directly affect the data plane.

Databricks has released a security update to address CVE-2020-13949. The update was first included in Databricks Runtime 7.3 LTS and is also included in all subsequent LTS releases, including 10.4 LTS.

If you are using a Databricks runtime version earlier than 7.3 LTS, you should upgrade to a newer LTS release that includes the security update. Additionally, if you are running your own Apache Tomcat instances, you should ensure that they are patched or updated to address this vulnerability.