CVE-2023-33891
published 2023-07-12CVE-2023-33891: In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.10%
0.9th percentile
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | spark | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| unisoc_technologies_co_ltd | sc9863a_sc9832e_sc7731e_t610_t310_t606_t760_t610_t618_t606_t612_t616_t760_t770_t | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ghsa8.8HIGH
cisa8.8HIGH
vendor_apache8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vgq4-vjqj-j4p9: In telephony service, there is a missing permission check
ghsa_unreviewed·2023-07-12
CVE-2023-33891 [MEDIUM] CWE-862 GHSA-vgq4-vjqj-j4p9: In telephony service, there is a missing permission check
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
GHSA
Apache Spark UI vulnerable to Command Injection
ghsa·2023-05-02·CVSS 8.8
CVE-2023-32007 [HIGH] CWE-77 Apache Spark UI vulnerable to Command Injection
Apache Spark UI vulnerable to Command Injection
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This issue was disclosed earlier as CVE-2022-33891, but incorrectly claimed version 3.1.3 (which has since gone EOL) would not be affected
CISA
Apache Spark Command Injection Vulnerability
cisa·2023-03-07·CVSS 8.8
CVE-2022-33891 [HIGH] CWE-78 Apache Spark Command Injection Vulnerability
Vulnerability: Apache Spark Command Injection Vulnerability
Affected: Apache Spark
Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
Required Action: Apply updates per vendor instructions.
Notes: https://lists.apache.org/thread/p847l3kopoo5bjtmxrcwk21xp6tjxqlc; https://nvd.nist.gov/vuln/detail/CVE-2022-33891
Remediation Due Date: 2023-03-28
Apache
Apache spark: CVE-2023-32007
vendor_apache·CVSS 8.8
CVE-2023-32007 [HIGH] Apache spark: CVE-2023-32007
Apache spark: CVE-2023-32007
This CVE is only an update to CVE-2022-33891 to clarify that version 3.1.3 is also affected. It is otherwise not a new vulnerability. Note that Apache Spark 3.1.x is EOL now.
Affected versions: 3.1.3
Apache
Apache spark: CVE-2022-33891
vendor_apache·CVSS 8.8
CVE-2022-33891 [HIGH] Apache spark: CVE-2022-33891
Apache spark: CVE-2022-33891
Severity: Important Vendor: The Apache Software Foundation Versions Affected: 3.1.3 and earlier (previously, this was marked as fixed in 3.1.3; this change is tracked as CVE-2023-32007 ) 3.2.0 to 3.2.1 Description: The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell comm
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-12
Published