Vulnerability record · CVE-2023-32007 · published 2 May 2023
CVE-2023-32007: Apache Spark UI ACL impersonation leads to shell command injection
Apache · Spark
When spark.acls.enable is on, a code path in Apache Spark's HttpSecurityFilter lets a user impersonate an arbitrary username. That impersonated name reaches a permission check that builds a Unix shell command from the input and executes it, giving command execution as the Spark process user. The record notes this only affects unsupported Spark versions and was previously mis-scoped under CVE-2022-33891.
Description
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This issue was disclosed earlier as CVE-2022-33891, but incorrectly claimed version 3.1.3 (which has since gone EOL) would not be affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Users are recommended to upgrade to a supported version of Apache Spark, such as version 3.4.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable command injection with high confidentiality, integrity and availability impact and a very high EPSS score, though it requires ACLs enabled and affects only unsupported versions.
What it is
When spark.acls.enable is on, a code path in Apache Spark's HttpSecurityFilter lets a user impersonate an arbitrary username. That impersonated name reaches a permission check that builds a Unix shell command from the input and executes it, giving command execution as the Spark process user. The record notes this only affects unsupported Spark versions and was previously mis-scoped under CVE-2022-33891.
Impact
An attacker gains arbitrary shell command execution with the privileges of the user running Spark, which can lead to full compromise of the Spark host and any data or credentials it can reach.
Attack surface
Reachable over the network through the Spark UI when ACLs are enabled; the CVSS vector indicates low privileges are required and no user interaction. The description does not state whether the attacker must already hold a valid account, only that impersonation of an arbitrary username is possible.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.75955, 99.5th percentile), indicating elevated likelihood of exploitation. References are vendor advisories and mailing lists only, with no public exploit tag.
What to do
- Upgrade to a supported Apache Spark release such as 3.4.0 or later; the affected versions are end-of-life and will not receive fixes.
- If upgrade is not immediately possible, disable spark.acls.enable where ACL enforcement is not required, or restrict Spark UI access to trusted networks only.
- Place the Spark UI behind an authenticating reverse proxy and network controls so only authorized users can reach it.
- Run Spark under a dedicated low-privilege service account with no access to sensitive files or credentials.
- Monitor Apache security advisories for supported-version guidance since this CVE is marked unsupported when assigned.
Detection
- Alert on unexpected child processes spawned by the Spark process, especially shell interpreters (sh, bash) or commands containing user-supplied strings.
- Audit Spark UI access logs for requests carrying unusual or arbitrary username values in impersonation-related parameters.
- Monitor for outbound connections or file writes from the Spark host that do not match normal job behavior.
- Verify spark.acls.enable configuration across Spark deployments and flag hosts still running unsupported versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2023/05/02/1 | Mailing List |
| https://lists.apache.org/thread/poxgnxhhnzz735kr1wos366l5vdbb0nv | Mailing List |
| https://spark.apache.org/security.html | Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2022-33891 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2023/05/02/1 | Mailing List |
| https://lists.apache.org/thread/poxgnxhhnzz735kr1wos366l5vdbb0nv | Mailing List |
| https://spark.apache.org/security.html | Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2022-33891 | Third Party Advisory |
Track CVE-2023-32007 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32007), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.