Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Spark | < 3.2.2 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2022/11/01/14Mailing List
- https://lists.apache.org/thread/60mgbswq2lsmrxykfxpqq13ztkm2ht6qMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/01/14Mailing List
- https://lists.apache.org/thread/60mgbswq2lsmrxykfxpqq13ztkm2ht6qMailing ListThird Party Advisory
FAQ
What is CVE-2022-31777?
CVE-2022-31777 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a mal...
How severe is CVE-2022-31777?
CVE-2022-31777 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31777?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Spark.