CVE-2022-33891 is a critical vulnerability in Apache Spark versions 3.0.3 and earlier, 3.1.1 to 3.1.2, and 3.2.0 to 3.2.1. It allows for arbitrary shell command execution as the Spark user when ACLs are enabled, due to an impersonation flaw in the HttpSecurityFilter. With a CVSS score of 8.8 (HIGH), this vulnerability is easily exploitable over the network with low privileges and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. This flaw is actively exploited in the wild, with exploit modules available in Metasploit and Nuclei, and has garnered significant community discussion and media coverage, including its use by the Zerobot malware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.3CPE matchmatch criteria | cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* | ||
>= 3.1.1, <= 3.1.2CPE matchmatch criteria | cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* | ||
>= 3.2.0, <= 3.2.1CPE matchmatch criteria | cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Spark UI can allow impersonation if ACLs enabled
Jul 19, 2022Apache Spark UI can allow impersonation if ACLs enabled
Jul 19, 2022apache-spark: Apache Spark shell command injection vulnerability via Spark UI
Jul 18, 2022