Description
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
No analysis available yet.
Remediation
Vendor Workaround
Upgrade to Apache Spark maintenance releases 3.2.2, or 3.3.1 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0218 | A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI. |
Github GHSA |
GHSA-43xg-8wmj-cw8h | Apache Spark vulnerable to Log Injection |
References
History
Tue, 06 May 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-05-06T03:36:31.908Z
Reserved: 2022-05-27T00:00:00.000Z
Link: CVE-2022-31777
Updated: 2024-08-03T07:26:01.073Z
Status : Modified
Published: 2022-11-01T16:15:13.367
Modified: 2025-05-06T04:16:00.257
Link: CVE-2022-31777
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA