Stored cross-site scripting in Apache Spark - CVE-2022-31777

 

Stored cross-site scripting in Apache Spark - CVE-2022-31777

Published: November 1, 2022


Vulnerability identifier: #VU68906
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2022-31777
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in log viewer UI. A remote attacker can permanently inject arbitrary JavaScript code into the application logs and execute it in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Apache Spark
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
Cloudera Observability with IBM
Red Hat Camel for Spring Boot
IBM Watson Discovery for IBM Cloud Pak for Data

How to mitigate CVE-2022-31777

Install update from vendor's website.

Apache Spark - addressed in versions 3.2.2, 3.3.1
Cloudera Observability with IBM - update to 3.5.3
Red Hat Camel for Spring Boot - update to 3.20.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2

External References

Related Security Bulletins