Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2022-33891

Apache | SparkAdded 2023-03-07Remediation Deadline 2023-03-28

Apache Spark Command Injection Vulnerability

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-78

References