Apache SparkGHSA-43xg-8wmj-cw8h
Apache Spark vulnerable to Log Injection
Medium5.4CVE-2022-31777 · Published Nov 1, 2022 · updated Dec 18, 2025
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.spark:spark-core_2.12 Maven | < 3.2.2 | 3.2.2 |
| >= 3.3.0, < 3.3.1 | 3.3.1 | |
| org.apache.spark:spark-core_2.13 Maven | < 3.2.2 | 3.2.2 |
| >= 3.3.0, < 3.3.1 | 3.3.1 | |
| pyspark PyPI | < 3.2.2 | 3.2.2 |
| >= 3.3.0, < 3.3.1 | 3.3.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-74
- Also known as
- BIT-spark-2022-31777, CVE-2022-31777, PYSEC-2022-42976
- nvd.nist.gov/vuln/detail/CVE-2022-31777
- github.com/apache/spark/commit/ad90195de56688ce0898691eb9d04297ab0871ad
- github.com/apache/spark
- github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2022-42976.yaml
- lists.apache.org/thread/60mgbswq2lsmrxykfxpqq13ztkm2ht6q
- web.archive.org/web/20220728105026/https://issues.apache.org/jira/browse/SPARK-39505
- www.openwall.com/lists/oss-security/2022/11/01/14
More Apache Spark advisories
All Apache Spark| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 152025 | Apache Spark has Inadequate Encryption Strength | Low | 3.4.4+1 more |
| May 22023 | Apache Spark UI vulnerable to Command Injection | High8.8 | 3.2.2 |
| Apr 172023 | Apache Spark vulnerable to Improper Privilege Management | Critical9.9 | 3.3.2+1 more |
| Jul 192022 | Apache Spark UI can allow impersonation if ACLs enabled | High8.8 | 3.1.3+1 more |
| Mar 112022 | Authentication Bypass by Capture-replay in Apache Spark | High7.5 | 3.1.3 |
| Feb 102022 | Improper Authentication in Apache Spark | Critical9.8 | 2.4.6 |