Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-31777


A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.


Published

2022-11-01T16:15:13.367

Last Modified

2025-05-06T04:16:00.257

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-74

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache spark < 3.2.2 Yes
Application apache spark 3.3.0 Yes

References