CyberRota Analysis
AI-GeneratedThe Spark History Server prior to version 3.5.8 is vulnerable to a lack of XSS escaping, allowing a malicious Spark job to inject arbitrary unescaped frontend code, which could lead to minimal privilege escalation in a user's browser. This vulnerability requires users to have the ability to launch Spark jobs and to trick higher-privileged users into accessing the affected web page. Organizations using Spark should prioritize upgrading to version 3.5.8 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later.
Related CVEs
Other vulnerabilities affecting the same vendor(s)