Apache Spark

Software updated 5 months ago (2024-05-04T20:31:25.340Z)
Download STIX
Preview STIX
Apache Spark is a powerful open-source, distributed computing system used for big data processing and analytics. It offers an interface for programming entire clusters with implicit data parallelism and fault tolerance. Developed by Matei Zaharia at the University of California, Berkeley's AMPLab, Apache Spark has gained significant popularity in the data science community due to its speed and ease of use. Recently, it has been leveraged for financial time series forecasting using streaming data analytics, demonstrating its versatility and applicability across various sectors. However, despite its widespread usage, Apache Spark has faced security vulnerabilities. Notably, CVE-2022-33891, a shell command injection vulnerability via Spark UI, was disclosed on July 17, 2022, on the Apache Spark security page and the oss-sec mailing list. This flaw allows remote attackers to execute arbitrary shell commands. The US Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities Catalog due to active exploitation. Further investigation by Flashpoint revealed that Apache Spark version 3.1.3 remained vulnerable to this issue despite vendor claims to the contrary. The vulnerability, CVE-2022-33891, has also been exploited by malware variants to spread and enhance their attack capabilities. Microsoft identified one such variant that exploits vulnerabilities in both Apache and Apache Spark. The severity of this issue is underscored by its high Common Vulnerability Scoring System (CVSS) score of 8.8. As of now, users are advised to take precautionary measures while deploying Apache Spark, especially version 3.1.3, until a comprehensive fix is provided by the vendor.
Description last updated: 2024-05-04T20:31:25.311Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Spark is a possible alias for Apache Spark. "Spark" refers to various concepts in different contexts. In cybersecurity, Spark is a Remote Access Trojan (RAT) used by the hacking group ExCobalt as part of their attack chain, which also includes tools like Mimikatz, ProcDump, SMBExec, Metasploit, and rsocx. This malware can infiltrate systems w
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Vulnerability
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Vulnerabilities
To see the evidence that has resulted in these vulnerability associations, create a free account
Alias DescriptionAssociation TypeVotes
The vulnerability CVE-2022-33891 is associated with Apache Spark. Unspecified
2
Source Document References
Information about the Apache Spark Software was read from the documents corpus below. This display is limited to 20 results, create a free account to see more