Impact
The Spark History Server prior to version 3.5.8 does not escape certain user‑supplied strings, allowing a malicious job to embed arbitrary HTML or JavaScript into the web interface. This flaw can be exploited to execute arbitrary code in the victim’s browser, effectively raising the attacker’s privileges from a low‑level job executor to the higher‑privilege user who views the history page. The vulnerability is a classic Cross‑Site Scripting flaw.
Affected Systems
Apache Spark History Server running Apache Spark versions before 3.5.8, such as 3.5.4, is affected by this issue.
Risk and Exploitability
The CVSS score is 6.1; exploitation requires the ability to submit a Spark job, which typically demands cluster or admin level permissions, and a victim user with higher privileges must be lured to view the history page. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate risk that hinges on multiple preconditions and reduces the likelihood of widespread attacks.
OpenCVE Enrichment