CVE-2023-32007
Last modified
CVE-2023-32007 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. EPSS estimates a 75.79% chance of exploitation in the next 30 days.
Description
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This issue was disclosed earlier as CVE-2022-33891, but incorrectly claimed version 3.1.3 (which has since gone EOL) would not be affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Users are recommended to upgrade to a supported version of Apache Spark, such as version 3.4.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Spark | <= 3.0.3 |
| Apache | Spark | >= 3.1.1, <= 3.1.3 |
| Apache | Spark | >= 3.2.0, <= 3.2.1 |
References
- https://spark.apache.org/security.htmlVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-33891Third Party Advisory
- https://spark.apache.org/security.htmlVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-33891Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-32007?
How severe is CVE-2023-32007?
How do I fix CVE-2023-32007?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-32001Rejected reason: We issued this CVE pre-maturely, as we have…
- CVE-2023-32002The use of `Module._load()` can bypass the policy mechanism …9.8
- CVE-2023-32003`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass …5.3
- CVE-2023-32004A vulnerability has been discovered in Node.js version 20, s…8.8
- CVE-2023-32005A vulnerability has been identified in Node.js version 20, a…5.3
- CVE-2023-32006The use of `module.constructor.createRequire()` can bypass t…8.8
- CVE-2023-32008Windows Resilient File System (ReFS) Remote Code Execution V…7.8
- CVE-2023-32009Windows Collaborative Translation Framework Elevation of Pri…8.8
- CVE-2023-3201The MStore API plugin for WordPress is vulnerable to Cross-S…4.3
- CVE-2023-32010Windows Bus Filter Driver Elevation of Privilege Vulnerabili…7
- CVE-2023-32011Windows iSCSI Discovery Service Denial of Service Vulnerabil…7.5
- CVE-2023-32012Windows Container Manager Service Elevation of Privilege Vul…7.8
Are you affected by CVE-2023-32007?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
