Open Source Security mailing list@oss_securityDisclosure
The post discloses a code‑execution vulnerability (CVE‑2025‑54920) in Apache Spark's History Server caused by permissive Jackson deserialization, but it does not provide PoC, exploit code, or patch information.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashGeneral
Alert announces CVE‑2025‑54920, an Apache Spark History Server code execution vulnerability, and links to an Intel Report, but provides no exploitation or mitigation information.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The tweet merely notes CVE‑2025‑54920 and links to external pages for vulnerability details and alert services, offering no additional technical, exploit, or mitigation information.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashGeneral
The alert announces CVE-2025‑54920, a code‑execution flaw in Apache Spark History Server, and points to an Intel report, but offers no PoC, exploit, patch, or evidence of active exploitation.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
Alert announces CVE-2025-54920, a code‑execution vulnerability in Apache Spark’s History Server, with an Intel report linked but no PoC, exploit code, or patch details.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The alert announces CVE-2025-54920, a code execution vulnerability in Apache Spark History Server, and provides a link to an Intel report for further details.
CVE@CVEnewPatch
CVE-2025-54920 affects Apache Spark versions before 3.5.7 and 4.0.1; the advisory recommends upgrading to patched versions. No PoC, exploit, or active exploitation is mentioned.