CVE Published: 01/11/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Spark Status : PUBLISHED
CVE-2022-31777 Description
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
CWE-ID: CWE-74 CWE Name: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (
Injection
) Source: Apache Software Foundation
Common Attack Pattern Enumeration and Classification (CAPEC)