Apache Spark: Shell command injection via Spark UI
Published May 2, 2023
8.7
HIGHCVSS 4.0
EPSS 75.95%
Description
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This issue was disclosed earlier as CVE-2022-33891, but incorrectly claimed version 3.1.3 (which has since gone EOL) would not be affected.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Users are recommended to upgrade to a supported version of Apache Spark, such as version 3.4.0.
Affected products
-
- Version 3.1.1StatusaffectedConstraints<3.2.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Spark | unaffected |
|
-
- Version 3.1.1StatusaffectedConstraints<3.2.2
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 15, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 75.95% (0.75955) | 99.52th | v5 (v2026.06.15) |
| Jun 15, 2026 | 75.79% (0.75792) | 99.46th | v5 (v2026.06.15) |
| Jan 10, 2026 | 92.17% (0.92167) | 99.69th | v4 (v2025.03.14) |
| Nov 21, 2025 | 91.16% (0.91155) | 99.62th | v4 (v2025.03.14) |
| Nov 18, 2025 | 92.58% (0.92579) | 99.80th | v4 (v2025.03.14) |
| Apr 15, 2025 | 91.16% (0.91155) | 99.61th | v4 (v2025.03.14) |
| Mar 17, 2025 | 92.58% (0.92579) | 99.74th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.00% (0.01005) | 84.32th | v3 (v2023.03.01) |
| May 21, 2024 | 1.47% (0.01475) | 86.74th | v3 (v2023.03.01) |
| May 8, 2024 | 1.95% (0.01947) | 88.62th | v3 (v2023.03.01) |
| Apr 13, 2024 | 1.14% (0.01142) | 84.53th | v3 (v2023.03.01) |
| Feb 14, 2024 | 0.46% (0.00464) | 74.71th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.33% (0.00327) | 70.07th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.36% (0.00357) | 68.25th | v3 (v2023.03.01) |
| Jun 4, 2023 | 0.41% (0.00415) | 70.37th | v3 (v2023.03.01) |
| May 11, 2023 | 0.29% (0.00293) | 64.55th | v3 (v2023.03.01) |
| May 3, 2023 | 0.04% (0.00045) | 12.26th | v3 (v2023.03.01) |
References (8)
- http://www.openwall.com/lists/oss-security/2023/05/02/1 Mailing List
- https://github.com/advisories/GHSA-59hw-j9g6-mfg3 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2023-72.yaml
- https://lists.apache.org/thread/poxgnxhhnzz735kr1wos366l5vdbb0nv vendor-advisoryMailing List
- https://nvd.nist.gov/vuln/detail/CVE-2023-32007
- https://spark.apache.org/security.html vendor-advisoryVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-33891 relatedThird Party Advisory
- https://www.openwall.com/lists/oss-security/2023/05/02/1
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2023/05/02/1 | Mailing List | |
| https://github.com/advisories/GHSA-59hw-j9g6-mfg3 | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2023-72.yaml | ||
| https://lists.apache.org/thread/poxgnxhhnzz735kr1wos366l5vdbb0nv | vendor-advisoryMailing List | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-32007 | ||
| https://spark.apache.org/security.html | vendor-advisoryVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-33891 | relatedThird Party Advisory | |
| https://www.openwall.com/lists/oss-security/2023/05/02/1 |
Change history (0)
No recorded changes yet.