Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-31777

Опубликовано: 01 нояб. 2022
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.

A stored cross-site scripting (XSS) flaw was found in Apache Spark. This issue allows an attacker to execute arbitrary JavaScript in the web browser of a user, including a malicious payload into the logs which are returned in logs rendered in the UI.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7apache-sparkWill not fix
Red Hat Integration Camel K 1apache-sparkWill not fix
Red Hat Integration Camel Quarkus 1apache-sparkWill not fix
Red Hat JBoss Data Grid 7apache-sparkOut of support scope
RHINT Camel-Springboot 3.20.1apache-sparkFixedRHSA-2023:210003.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-74
https://bugzilla.redhat.com/show_bug.cgi?id=2145264apache-spark: XSS vulnerability in log viewer UI Javascript

EPSS

Процентиль: 32%
0.00126
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.

CVSS3: 5.4
debian
больше 3 лет назад

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2. ...

CVSS3: 5.4
github
больше 3 лет назад

Apache Spark vulnerable to Log Injection

EPSS

Процентиль: 32%
0.00126
Низкий

5.4 Medium

CVSS3