Sept. 1, 2022, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Azure Synapse Analytics is an analytics service for processing data using various runtimes,
among them Apache Spark. Synapse provided users the capability to mount Azure File Shares to
their Apache Spark Pools via a script called filesharemount.sh that would execute with elevated
privileges. This script would mount the File Share to the /synfs directory. There was a race
condition in the script where, if successfully exploited, a user could execute the chown command
to change the ownership of any directory—including …

lpe spark synapse

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States