CISA Known Exploited Vulnerability

CVE-2022-33891

Apache · Spark

Apache Spark Command Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Unknown

CISA description

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

Required action

Apply updates per vendor instructions.