← Vulnerability feed

Vulnerability record · CVE-2023-32007 · published 2 May 2023

CVE-2023-32007: Apache Spark UI ACL impersonation leads to shell command injection

Apache · Spark

When spark.acls.enable is on, a code path in Apache Spark's HttpSecurityFilter lets a user impersonate an arbitrary username. That impersonated name reaches a permission check that builds a Unix shell command from the input and executes it, giving command execution as the Spark process user. The record notes this only affects unsupported Spark versions and was previously mis-scoped under CVE-2022-33891.

8.8 CVSS 3.1 High EPSS 76% · top 0.5% CWE-77 · Command injection
8.8CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This issue was disclosed earlier as CVE-2022-33891, but incorrectly claimed version 3.1.3 (which has since gone EOL) would not be affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Users are recommended to upgrade to a supported version of Apache Spark, such as version 3.4.0.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityNetwork-reachable command injection with high confidentiality, integrity and availability impact and a very high EPSS score, though it requires ACLs enabled and affects only unsupported versions.

What it is

When spark.acls.enable is on, a code path in Apache Spark's HttpSecurityFilter lets a user impersonate an arbitrary username. That impersonated name reaches a permission check that builds a Unix shell command from the input and executes it, giving command execution as the Spark process user. The record notes this only affects unsupported Spark versions and was previously mis-scoped under CVE-2022-33891.

Impact

An attacker gains arbitrary shell command execution with the privileges of the user running Spark, which can lead to full compromise of the Spark host and any data or credentials it can reach.

Attack surface

Reachable over the network through the Spark UI when ACLs are enabled; the CVSS vector indicates low privileges are required and no user interaction. The description does not state whether the attacker must already hold a valid account, only that impersonation of an arbitrary username is possible.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.75955, 99.5th percentile), indicating elevated likelihood of exploitation. References are vendor advisories and mailing lists only, with no public exploit tag.

What to do

  • Upgrade to a supported Apache Spark release such as 3.4.0 or later; the affected versions are end-of-life and will not receive fixes.
  • If upgrade is not immediately possible, disable spark.acls.enable where ACL enforcement is not required, or restrict Spark UI access to trusted networks only.
  • Place the Spark UI behind an authenticating reverse proxy and network controls so only authorized users can reach it.
  • Run Spark under a dedicated low-privilege service account with no access to sensitive files or credentials.
  • Monitor Apache security advisories for supported-version guidance since this CVE is marked unsupported when assigned.

Detection

  • Alert on unexpected child processes spawned by the Spark process, especially shell interpreters (sh, bash) or commands containing user-supplied strings.
  • Audit Spark UI access logs for requests carrying unusual or arbitrary username values in impersonation-related parameters.
  • Monitor for outbound connections or file writes from the Spark host that do not match normal job behavior.
  • Verify spark.acls.enable configuration across Spark deployments and flag hosts still running unsupported versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32007 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-33891Apache Spark UI ACL impersonation leads to OS command injectionApache Spark's UI ACL feature (spark.acls.enable) contains a flaw in HttpSecurityFilter where a user can supply an arbitrary username to impersonate …KEVEPSS 93%analysed9.9CVE-2023-22946Apache spark improper privilege management vulnerabilityIn Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c…EPSS 1.1%9.8CVE-2020-9480Apache spark missing authentication for critical function vulnerabilityIn Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…EPSS 29%9.8CVE-2018-17190Apache spark vulnerabilityIn all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hos…EPSS 8.8%9.1CVE-2019-20445Netty http request smuggling vulnerabilityHttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-En…EPSS 13%8.8CVE-2025-54920Apache spark deserialization of untrusted data vulnerabilityThis issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.…EPSS 5.3%7.8CVE-2017-12612Apache spark deserialization of untrusted data vulnerabilityIn Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched …EPSS 0.73%7.5CVE-2021-38296Apache spark authentication bypass by capture-replay vulnerabilityApache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and ear…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2023-32007), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.