S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-33891 Scanner

CVE-2022-33891 scanner - OS Command Injection vulnerability in Apache Spark

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-33891
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Apache Sparkby Apache Software Foundation
3.0.3 and earlier
Updated Aug 22, 2026View on NVD →
Detail

Apache Spark is a widely used open-source distributed computing system that is designed to handle large-scale data processing. It can process data quickly across clusters with its in-memory processing capabilities and supports multiple programming languages, including Java, Python, and Scala. Apache Spark is commonly used for analytics, machine learning, and data processing tasks. The platform is popular because it’s fast, user-friendly, and can handle complex data processing tasks.

CVE-2022-33891 is a vulnerability that has been detected in Apache Spark. This vulnerability has been caused by enabling ACLs via the configuration option spark.acls.enable. When enabled, a malicious user can perform impersonation by providing an arbitrary user name, which passes through the authentication filter to determine whether the user has permissions to view or modify the application. A flaw in the HttpSecurityFilter mechanism allows a malicious user to execute arbitrary shell commands as the user that Spark is currently running as. This vulnerability affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.

Exploiting this vulnerability can lead to arbitrary shell command execution, and the attacker can gain full control of the Apache Spark framework. The attacker can leverage this control to extract sensitive information, disrupt services, and in some cases, maliciously alter the system settings to their advantage. A successful exploit of this vulnerability can also result in damage to the reputation of the organization, loss of revenue or intellectual property, and damage to customer trust.

The pro features of the s4e.io platform can be very useful for identifying vulnerabilities in digital assets. With real-time vulnerability scanning, customized alerts, and detailed reporting, s4e.io provides a comprehensive vulnerability management platform that can help ensure the security of your digital assets. Its intuitive interface and user-friendly design mean that even non-technical users can easily and quickly understand the vulnerabilities present in their systems and how to protect against them.

 

REFERENCES

Solution Advice

There are certain precautions that can be taken to protect against this vulnerability. Some of them include:

  • Disable spark.acls.enable configuration to limit the possibility of user impersonation.
  • Monitor access logs and identify suspicious activity.
  • Update to the latest version of Apache Spark and apply relevant security patches.
  • Establish strong network security measures and enforce strong authentication and access control protocols.
  • Regularly conduct vulnerability assessments and penetration testing to identify potential vulnerabilities and address them promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.