Apache
Apache Spark: vulnerabilidades y CVE
Apache Spark tiene 24 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 4 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses4
Críticas4
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-33891 | Alta (8.8) | 93% | ⚠ Explotación activa | 18 jul 2022 | The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-32773 | Media (6.1) | 0.68% | — | 2 sept 2026 | There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser.… |
| CVE-2026-18428 | Alta (8.7) | 1.00% | — | 13 ago 2026 | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a… |
| CVE-2025-54920 | Alta (8.8) | 5.3% | — | 16 mar 2026 | This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code… |
| CVE-2025-55039 | Media (6.5) | 0.24% | — | 15 oct 2025 | This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When… |
| CVE-2024-23945 | Media (5.9) | 1.6% | — | 23 dic 2024 | Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value,… |
| CVE-2023-32007 | Alta (8.8) | 76% | — | 2 may 2023 | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions… |
| CVE-2023-22946 | Crítica (9.9) | 1.1% | — | 17 abr 2023 | In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however,… |
| CVE-2022-31777 | Media (5.4) | 1.6% | — | 1 nov 2022 | A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into… |
| CVE-2022-33891 | Alta (8.8) | 93% | ⚠ Explotación activa | 18 jul 2022 | The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the… |
| CVE-2021-38296 | Alta (7.5) | 1.8% | — | 10 mar 2022 | Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for… |
| CVE-2020-27223 | Media (5.3) | 78% | — | 26 feb 2021 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may… |
| CVE-2020-27218 | Media (4.8) | 8.3% | — | 28 nov 2020 | In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed… |
| CVE-2020-9480 | Crítica (9.8) | 29% | — | 23 jun 2020 | In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the… |
| CVE-2019-20445 | Crítica (9.1) | 13% | — | 29 ene 2020 | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header. |
| CVE-2019-10172 | Alta (7.5) | 17% | — | 18 nov 2019 | A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes. |
| CVE-2019-10099 | Alta (7.5) | 1.3% | — | 7 ago 2019 | Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by… |
| CVE-2018-11760 | Media (5.5) | 0.60% | — | 4 feb 2019 | When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and… |
| CVE-2018-17190 | Crítica (9.8) | 8.8% | — | 19 nov 2018 | In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A… |
| CVE-2018-11804 | Alta (7.5) | 5.7% | — | 24 oct 2018 | Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including… |
| CVE-2018-11770 | Media (4.2) | 66% | — | 13 ago 2018 | From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property… |
| CVE-2018-8024 | Media (5.4) | 5.3% | — | 12 jul 2018 | In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing… |
| CVE-2018-1334 | Media (4.7) | 0.51% | — | 12 jul 2018 | In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark… |
| CVE-2017-12612 | Alta (7.8) | 0.73% | — | 13 sept 2017 | In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmatically using the launcher API potentially vulnerable to… |
| CVE-2017-7678 | Media (6.1) | 3.4% | — | 12 jul 2017 | In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits data including MHTML to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.