FixVibe

high

Apache Spark UI Command Injection via ACL Impersonation (CVE-2022-33891)

Apache Spark UI releases in affected version ranges can allow command execution through ACL impersonation handling when vulnerable runtime conditions are present. FixVibe GitHub repo scans flag affected Apache Spark dependencies.

CVE-2022-33891CVE-2023-32007GHSA-4x9r-j582-cgr8GHSA-59hw-j9g6-mfg3CWE-78

Impact

Apache Spark UI ACL impersonation handling can lead to command execution when an affected Spark runtime is deployed with the vulnerable UI conditions present [S1][S2]. The risk is most relevant for Spark clusters where the UI or control-plane surface is reachable by users outside the trusted operator boundary [S1].

Root Cause

The issue sits in Spark UI access-control and impersonation handling. When ACL-related checks are active, attacker-controlled impersonation input can reach a permission-check path that builds a Unix shell command [S1][S2]. This is tracked as CWE-78 [S2].

Affected Versions

  • Apache Spark 3.1.3 and earlier [S1].
  • Apache Spark 3.2.0 to 3.2.1 [S1].

Earlier advisory text treated Spark 3.1.3 as fixed, but Apache later clarified through CVE-2023-32007 that 3.1.3 is also affected [S1].

Fixes

Upgrade Apache Spark or PySpark to Spark 3.2.2, 3.3.0, or a currently supported later release [S1]. Rebuild the Spark drivers, workers, notebooks, batch images, and cluster artifacts that can start Spark, and keep Spark UIs plus submission/control-plane endpoints restricted to trusted private networks with strong authentication and authorization [S1].

Covered by FixVibe

FixVibe's GitHub repo scans flag Maven, Gradle and PySpark projects that depend on Apache Spark versions covered by CVE-2022-33891 / GHSA-4x9r-j582-cgr8 and the related CVE-2023-32007 correction, with the version, file and remediation guidance.