Vulnerabilities > Apache > Spark > 3.1.3

DATE CVE VULNERABILITY TITLE RISK
2023-05-02 CVE-2023-32007 Unspecified vulnerability in Apache Spark
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable.
network
low complexity
apache
8.8
2023-04-17 CVE-2023-22946 Unspecified vulnerability in Apache Spark
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges.
network
low complexity
apache
critical
9.9
2022-11-01 CVE-2022-31777 Unspecified vulnerability in Apache Spark
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
network
low complexity
apache
5.4