Apache Spark Command Injection Vulnerability
Vendor: Apache
Product: Spark
Added: 2023-03-07
Due Date: 2023-03-28
Description:
Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
Required Action:
Apply updates per vendor instructions.
CWEs: