Junglewise Threat Intelligence

CVE-2022-33891: Apache Spark OS command injection in Spark UI via impersonation

CVE-2022-33891 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-07-19

Technologies: pyspark (PyPI), Apache Spark. Vendors: PyPI, Apache.

Executive brief

Apache Spark is a popular data processing engine used for large-scale analytics. A security flaw in its web-based user interface allows an attacker to impersonate other users and execute unauthorized commands on the server. This could lead to a complete system takeover, data theft, or disruption of data processing operations.

Technical details

A command injection vulnerability exists in the Apache Spark UI's HttpSecurityFilter when Access Control Lists (ACLs) are enabled via 'spark.acls.enable'. The vulnerability is rooted in a code path that allows a user to provide an arbitrary username for impersonation. This input is subsequently used to construct a Unix shell command for permission checks without proper sanitization. An authenticated attacker can exploit this by submitting a crafted username containing shell metacharacters, leading to arbitrary command execution with the privileges of the user running the Spark process. The issue is resolved in Apache Spark version 3.2.2 and 3.1.3 (for pyspark).

Affected products

  • Apache Spark <= 3.0.3, 3.1.1 to 3.1.3, 3.2.0 to 3.2.1
  • Apache pyspark < 3.1.3, 3.2.0 to 3.2.1

Timeline

  • 2022-07-18: advisory: NVD publication date
  • 2022-07-19: disclosed: GitHub Advisory published
  • 2022-07-21: other: GitHub Advisory reviewed

References

Related threats