{"cveID":"CVE-2022-33891","vendorProject":"Apache","product":"Spark","vulnerabilityName":"Apache Spark Command Injection Vulnerability","dateAdded":"2023-03-07","shortDescription":"Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-03-28","knownRansomwareCampaignUse":"Unknown","notes":"https://lists.apache.org/thread/p847l3kopoo5bjtmxrcwk21xp6tjxqlc;  https://nvd.nist.gov/vuln/detail/CVE-2022-33891","cwes":["CWE-78"],"year":2022,"state":"unmapped","stale_reasons":[],"mappings":[],"techniques":[],"mapping_types":[],"has_exploitation_technique":false,"mapping_attack_versions":[],"mapping_domains":[],"sigma_coverage":null,"sigma_rules_tagged_cve":["1a9a04fd-02d1-465c-abad-d733fd409f9c","c8a5f584-cdc8-42cc-8cce-0398e4265de3"],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}