EXPOSURES › CVE-2022-33891
CVE-2022-33891
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Spark exposed to command injection via UI with ACLs enabled, actively exploited in wild
An authenticated user could exploit a command injection vulnerability in Apache Spark's UI with Access Control Lists enabled to inject arbitrary SQL, potentially accessing unauthorized data. Users should upgrade immediately to a patched version.
Shame score — Active exploitation of a critical vulnerability in a widely used product by the DIB, leading to potential unauthorized data access and a breach of trust.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.