V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-33891
DEB
High KEVConfirmedExploit available

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, th…

CVSS
8.8
High
EPSS
0.93
p99
Published
2022-01-01
Updated
2023-03-07
Description

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.

Tags · CWE
KEV
CWE-77
CWE-78
CAPEC-6
CAPEC-15
CAPEC-40
CAPEC-43
CAPEC-75
CAPEC-76
CAPEC-88
CAPEC-108
CAPEC-136
CAPEC-183
CAPEC-248
Affected products
Spark ≤ 3.0.3Spark 3.1.1–3.1.2Spark 3.2.0–3.2.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2022-01-01
Published
2023-03-07
Added to KEV
2023-03-07
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.930 · p99
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2022-33891
github-poc · https://github.com/asepsaepdin/CVE-2022-33891
Enterprise
Affected products
ProductVendorStatus
apache-sparkExploited
spark*Exploited
Source databases
DEB
CVE
Related vulnerabilities