Vulnerability CVE-2022-31777


Published: 2022-11-01

Description:
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.

Type:

CWE-74

 References:
https://lists.apache.org/thread/60mgbswq2lsmrxykfxpqq13ztkm2ht6q

Copyright 2026, cxsecurity.com

 

Back to Top