Junglewise Threat Intelligence

CVE-2023-22946: PYSEC-2023-44 - In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The appl

CVE-2023-22946 · Severity: low · CVSS 3.1 · Published 2023-04-17

Technologies: pyspark (PyPI), Apache Spark. Vendors: Maven, PyPI, Apache.

Executive brief

Apache Spark is a distributed data processing framework used for large-scale analytics. A vulnerability in versions before 3.4.0 and 3.3.3 allows applications submitted with a restricted proxy user to bypass those restrictions by injecting malicious classes into the classpath, effectively escalating to the privileges of the submitting user. This is particularly dangerous in shared cluster environments managed by tools like Apache Livy.

Technical details

This is an improper privilege management vulnerability (CWE-269) affecting Apache Spark's proxy-user authentication mechanism. When applications are submitted using spark-submit with a proxy-user parameter to limit privileges, an attacker can bypass this restriction by providing malicious configuration-related classes on the classpath. The vulnerability exists because Spark did not properly validate classpath entries in cluster mode when proxy-user was enabled. An authenticated attacker with the ability to submit applications can execute arbitrary code with the submitting user's privileges rather than the restricted proxy-user. The issue is fixed in versions 3.4.0, 3.3.3, and later by introducing the configuration parameter spark.submit.proxyUser.allowCustomClasspathInClusterMode, which defaults to false to prevent custom classpath injection.

Affected products

  • Apache Spark 2.0 through 3.3.2 (excluding 3.3.3, 3.4.0+)
  • Apache PySpark 2.1.1 through 3.3.1 (excluding 3.3.2+)

Timeline

  • 2023-04-17: disclosed: GHSA and CVE published
  • 2023-04-17: patched: Apache Spark 3.3.3 and 3.4.0 released with fix

References

Related threats