CVE-2022-33891

Confirmed PUBLISHED

Apache Spark shell command injection vulnerability via Spark UI

Apache Software Foundation · Apache Spark
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High EPSS 93.0%

At a Glance

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.

metasploit nuclei_scanner cisa apache
CVE Published
Jul 18, 2022
Exploitation Reported
Mar 07, 2023
CVSS
8.8 High
EPSS
93.0%
Remote Low complexity No user interaction

Affected Versions

Vendor Product Version Status
Apache Software Foundation
Apache Spark

3.0.3 and earlier to <= 3.0.3

Affected
Apache Software Foundation
Apache Spark

3.1.1 to 3.1.2 to <= 3.1.2

Affected
Apache Software Foundation
Apache Spark

3.2.0 to 3.2.1 to <= 3.2.1

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.