CVE-2023-22946
CRITICAL9.9EPSS 0.44%Apache Spark proxy-user privilege escalation from malicious configuration class
發布日:2023/4/17修改日:2025/10/9
描述
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however, by providing malicious configuration-related classes on the classpath. This affects architectures relying on proxy-user, for example those using Apache Livy to manage submitted applications. Update to Apache Spark 3.4.0 or later, and ensure that spark.submit.proxyUser.allowCustomClasspathInClusterMode is set to its default of "false", and is not overridden by submitted applications.
受影響套件(5)
- Bitnami/sparkfrom 0, < 3.4.0
- Maven/org.apache.spark:spark-core_2.12from 0, < 3.3.3
- Maven/org.apache.spark:spark-core_2.13from 0, < 3.3.3
- PyPI/pysparkfrom 0, < 3.3.2
- PyPI/pysparkfrom 0, < 3.4.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.9 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
參考連結(9)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-22946
- PATCHhttps://github.com/apache/spark
- WEBhttps://github.com/apache/spark/commit/909da96e1471886a01a9e1def93630c4fd40e74a
- WEBhttps://github.com/apache/spark/pull/39474
- WEBhttps://github.com/apache/spark/pull/41428
- WEBhttps://github.com/degant/spark/commit/bfba57724d2520e0fcaa7990f7257c21d11cd75a
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2023-44.yaml
- WEBhttps://issues.apache.org/jira/browse/SPARK-41958
- WEBhttps://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv