Vulnerability record

CVE-2022-33891

Apache Spark Command Injection Vulnerability

Severity: HighExploitation: Exploitation confirmedCISA KEV
What should I do?

This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Spark, fix it now.

CISA required action: Apply updates per vendor instructions.

US federal civilian agencies must remediate by Mar 28, 2023.

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations and CISA's required action, limit exposure of affected systems, and watch this record for a patch.

Description

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Affected products

Products affected by this vulnerability, with versions and the source of each entry
ProductVendorAffected versionsSource
SparkApache Software Foundation<= 3.0.3; >= 3.1.1, <= 3.1.2; >= 3.2.0, <= 3.2.1KEV

Sources: KEV = CISA Known Exploited Vulnerabilities catalog.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdateKEV

    CVE-2022-33891 scored CVSS 8.8: Apache Spark, Apache Spark Command Injection Vulnerability

    CISA lists this as exploited in the wild. Unpatched Spark systems are exposed to active attacks now.

    Basis: NIST National Vulnerability Database

1 earlier event is available with a subscription. See plans.

Coverage

We have not published a story about this vulnerability yet.

References

  • lists.apache.org https://lists.apache.org/thread/p847l3kopoo5bjtmxrcwk21xp6tjxqlc
  • nvd.nist.gov https://nvd.nist.gov/vuln/detail/CVE-2022-33891
  • packetstormsecurity.com http://packetstormsecurity.com/files/168309/Apache-Spark-Unauthenticated-Command-Injection.html
  • openwall.com http://www.openwall.com/lists/oss-security/2023/05/02/1
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-33891