CVE-2022-31777: Apache Spark XSS vulnerability in log viewer UI Javascript
A stored cross-site scripting (XSS) flaw was found in Apache Spark. This issue allows an attacker to execute arbitrary JavaScript in the web browser of a user, including a malicious payload into the logs which are returned in logs rendered in the UI.
Other sources
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31777?
CVE-2022-31777 is a stored cross-site scripting (XSS) vulnerability in Apache Spark that allows remote attackers to execute arbitrary JavaScript in the user's web browser.
How does CVE-2022-31777 impact users?
CVE-2022-31777 allows attackers to execute malicious JavaScript code in the web browser of a user, potentially leading to unauthorized access or data theft.
Which versions of Apache Spark are affected by CVE-2022-31777?
Apache Spark versions 3.2.1 and earlier, and 3.3.0 are affected by CVE-2022-31777.
How can I remediate CVE-2022-31777 in Apache Spark?
To remediate CVE-2022-31777 in Apache Spark, upgrade to version 3.2.2 or 3.3.1 depending on the affected version.
Where can I find more information about CVE-2022-31777?
You can find more information about CVE-2022-31777 in the following references: [CVE-2022-31777](https://www.cve.org/CVERecord?id=CVE-2022-31777), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-31777), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2145264), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2023:2100).