{"id":"GHSA-43xg-8wmj-cw8h","summary":"Apache Spark vulnerable to Log Injection","details":"A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.","aliases":["BIT-spark-2022-31777","CVE-2022-31777","PYSEC-2022-42976"],"modified":"2025-12-18T16:17:11.831234Z","published":"2022-11-01T19:00:29Z","database_specific":{"github_reviewed_at":"2022-11-01T21:03:46Z","github_reviewed":true,"nvd_published_at":"2022-11-01T16:15:00Z","severity":"MODERATE","cwe_ids":["CWE-74"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31777"},{"type":"WEB","url":"https://github.com/apache/spark/commit/ad90195de56688ce0898691eb9d04297ab0871ad"},{"type":"PACKAGE","url":"https://github.com/apache/spark"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2022-42976.yaml"},{"type":"WEB","url":"https://lists.apache.org/thread/60mgbswq2lsmrxykfxpqq13ztkm2ht6q"},{"type":"WEB","url":"https://web.archive.org/web/20220728105026/https://issues.apache.org/jira/browse/SPARK-39505"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/11/01/14"}],"affected":[{"package":{"name":"pyspark","ecosystem":"PyPI","purl":"pkg:pypi/pyspark"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.2"}]}],"versions":["2.1.1","2.1.2","2.1.3","2.2.0","2.2.1","2.2.2","2.2.3","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","3.0.0","3.0.1","3.0.2","3.0.3","3.1.1","3.1.2","3.1.3","3.2.0","3.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-43xg-8wmj-cw8h/GHSA-43xg-8wmj-cw8h.json"}},{"package":{"name":"pyspark","ecosystem":"PyPI","purl":"pkg:pypi/pyspark"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.0"},{"fixed":"3.3.1"}]}],"versions":["3.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-43xg-8wmj-cw8h/GHSA-43xg-8wmj-cw8h.json"}},{"package":{"name":"org.apache.spark:spark-core_2.9.3","ecosystem":"Maven","purl":"pkg:maven/org.apache.spark/spark-core_2.9.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.0-incubating","0.8.1-incubating"],"database_specific":{"last_known_affected_version_range":"\u003c 3.2.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-43xg-8wmj-cw8h/GHSA-43xg-8wmj-cw8h.json"}},{"package":{"name":"org.apache.spark:spark-core_2.13","ecosystem":"Maven","purl":"pkg:maven/org.apache.spark/spark-core_2.13"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.2"}]}],"versions":["3.2.0","3.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-43xg-8wmj-cw8h/GHSA-43xg-8wmj-cw8h.json"}},{"package":{"name":"org.apache.spark:spark-core_2.13","ecosystem":"Maven","purl":"pkg:maven/org.apache.spark/spark-core_2.13"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.0"},{"fixed":"3.3.1"}]}],"versions":["3.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-43xg-8wmj-cw8h/GHSA-43xg-8wmj-cw8h.json"}},{"package":{"name":"org.apache.spark:spark-core_2.12","ecosystem":"Maven","purl":"pkg:maven/org.apache.spark/spark-core_2.12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.2"}]}],"versions":["2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","3.0.0","3.0.0-preview","3.0.0-preview2","3.0.1","3.0.2","3.0.3","3.1.0","3.1.1","3.1.2","3.1.3","3.2.0","3.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-43xg-8wmj-cw8h/GHSA-43xg-8wmj-cw8h.json"}},{"package":{"name":"org.apache.spark:spark-core_2.12","ecosystem":"Maven","purl":"pkg:maven/org.apache.spark/spark-core_2.12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.0"},{"fixed":"3.3.1"}]}],"versions":["3.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-43xg-8wmj-cw8h/GHSA-43xg-8wmj-cw8h.json"}},{"package":{"name":"org.apache.spark:spark-core_2.11","ecosystem":"Maven","purl":"pkg:maven/org.apache.spark/spark-core_2.11"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.0","1.2.1","1.2.2","1.3.0","1.3.1","1.4.0","1.4.1","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.6.2","1.6.3","2.0.0","2.0.0-preview","2.0.1","2.0.2","2.1.0","2.1.1","2.1.2","2.1.3","2.2.0","2.2.1","2.2.2","2.2.3","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-43xg-8wmj-cw8h/GHSA-43xg-8wmj-cw8h.json","last_known_affected_version_range":"\u003c 3.2.2"}},{"package":{"name":"org.apache.spark:spark-core_2.10","ecosystem":"Maven","purl":"pkg:maven/org.apache.spark/spark-core_2.10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.0-incubating","0.9.1","0.9.2","1.0.0","1.0.1","1.0.2","1.1.0","1.1.1","1.2.0","1.2.1","1.2.2","1.3.0","1.3.1","1.4.0","1.4.1","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.6.2","1.6.3","2.0.0","2.0.0-preview","2.0.1","2.0.2","2.1.0","2.1.1","2.1.2","2.1.3","2.2.0","2.2.1","2.2.2","2.2.3"],"database_specific":{"last_known_affected_version_range":"\u003c 3.2.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-43xg-8wmj-cw8h/GHSA-43xg-8wmj-cw8h.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}