Skip to content
Apache SparkGHSA-43xg-8wmj-cw8h

Apache Spark vulnerable to Log Injection

Medium5.4CVE-2022-31777 · Published Nov 1, 2022 · updated Dec 18, 2025

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.spark:spark-core_2.12
Maven
< 3.2.23.2.2
>= 3.3.0, < 3.3.13.3.1
org.apache.spark:spark-core_2.13
Maven
< 3.2.23.2.2
>= 3.3.0, < 3.3.13.3.1
pyspark
PyPI
< 3.2.23.2.2
>= 3.3.0, < 3.3.13.3.1
Details and references

More Apache Spark advisories

All Apache Spark
Advisory
Apache Spark has Inadequate Encryption Strength
LowOct 15, 2025
Apache Spark UI vulnerable to Command Injection
High8.8May 2, 2023
Apache Spark vulnerable to Improper Privilege Management
Critical9.9Apr 17, 2023
Apache Spark UI can allow impersonation if ACLs enabled
High8.8Jul 19, 2022
Authentication Bypass by Capture-replay in Apache Spark
High7.5Mar 11, 2022
Improper Authentication in Apache Spark
Critical9.8Feb 10, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.