Impact
Apache Spark UI ACL impersonation handling can lead to command execution when an affected Spark runtime is deployed with the vulnerable UI conditions present [S1][S2]. The risk is most relevant for Spark clusters where the UI or control-plane surface is reachable by users outside the trusted operator boundary [S1].
Root Cause
The issue sits in Spark UI access-control and impersonation handling. When ACL-related checks are active, attacker-controlled impersonation input can reach a permission-check path that builds a Unix shell command [S1][S2]. This is tracked as CWE-78 [S2].
Affected Versions
- Apache Spark 3.1.3 and earlier [S1].
- Apache Spark 3.2.0 to 3.2.1 [S1].
Earlier advisory text treated Spark 3.1.3 as fixed, but Apache later clarified through CVE-2023-32007 that 3.1.3 is also affected [S1].
Fixes
Upgrade Apache Spark or PySpark to Spark 3.2.2, 3.3.0, or a currently supported later release [S1]. Rebuild the Spark drivers, workers, notebooks, batch images, and cluster artifacts that can start Spark, and keep Spark UIs plus submission/control-plane endpoints restricted to trusted private networks with strong authentication and authorization [S1].
Covered by FixVibe
FixVibe's GitHub repo scans flag Maven, Gradle and PySpark projects that depend on Apache Spark versions covered by CVE-2022-33891 / GHSA-4x9r-j582-cgr8 and the related CVE-2023-32007 correction, with the version, file and remediation guidance.
