This repository has been archived by the owner on Oct 2, 2023. It is now read-only.
CVE-2022-31777 (Medium) detected in spark-core_2.11-2.3.3.jar #136
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-31777 - Medium Severity Vulnerability
Vulnerable Library - spark-core_2.11-2.3.3.jar
The Apache Software Foundation provides support for the Apache community of open-source software projects. The Apache projects are characterized by a collaborative, consensus based development process, an open and pragmatic software license, and a desire to create high quality software that leads the way in its field. We consider ourselves not simply a group of projects sharing a server, but rather a community of developers and users.
Library home page: http://spark.apache.org/
Dependency Hierarchy:
Found in HEAD commit: 7b16df0bfd847c502ac80c1464fe08140edf5d0d
Found in base branch: master
Vulnerability Details
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
Publish Date: 2022-11-01
URL: CVE-2022-31777
CVSS 3 Score Details (5.4)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://lists.apache.org/thread/60mgbswq2lsmrxykfxpqq13ztkm2ht6q
Release Date: 2022-11-01
Fix Resolution: org.apache.spark:spark-core:3.2.2,3.3.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: