{"id":"PYSEC-2022-42976","details":"A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.","aliases":["BIT-spark-2022-31777","CVE-2022-31777","GHSA-43xg-8wmj-cw8h"],"modified":"2026-06-10T17:01:37.003052396Z","published":"2022-11-01T16:15:00Z","references":[{"type":"ARTICLE","url":"https://lists.apache.org/thread/60mgbswq2lsmrxykfxpqq13ztkm2ht6q"},{"type":"WEB","url":"https://lists.apache.org/thread/60mgbswq2lsmrxykfxpqq13ztkm2ht6q"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-43xg-8wmj-cw8h"}],"affected":[{"package":{"name":"pyspark","ecosystem":"PyPI","purl":"pkg:pypi/pyspark"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.2"}]}],"versions":["2.1.1","2.1.2","2.1.3","2.2.0","2.2.1","2.2.2","2.2.3","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","3.0.0","3.0.1","3.0.2","3.0.3","3.1.1","3.1.2","3.1.3","3.2.0","3.2.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pyspark/PYSEC-2022-42976.yaml"}}],"schema_version":"1.7.5"}