在 Spark 3.5.8 之前的 Spark History Server 中存在 XSS 转义缺失的问题,这使得恶意的 Spark 作业能够生成任意未转义的前端代码,从而可能导致浏览器中的最小权限提升。建议用户升级到 Spark 3.5.8 或更高版本。 该 CVE 被标记为“低”严重性,因为其利用路径需要同时满足两个条件:(1)攻击者需具备相对较高权限(即能够启动 Spark 作业);(2)需要诱骗拥有更高权限的用户登录并访问 Spark 历史页面。 建议用户将 Spark History Server 升级
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Spark | 3.0.0 ~ 3.5.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet