NA

CVE-2022-31777

Published: 01/11/2022 Updated: 29/11/2022
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and previous versions, and 3.3.0, allows remote malicious users to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache spark 3.3.0

apache spark

Vendor Advisories

Description<!---->A stored cross-site scripting (XSS) flaw was found in Apache Spark This issue allows an attacker to execute arbitrary JavaScript in the web browser of a user, including a malicious payload into the logs which are returned in logs rendered in the UIA stored cross-site scripting (XSS) flaw was found in Apache Spark This issue all ...