Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36389
HistoryJul 18, 2022 - 10:43 a.m.

OS Command Injection

2022-07-1810:43:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
68
apache spark
os command injection
unix shell command

EPSS

0.973

Percentile

99.9%

Apache Spark is vulnerable to OS command injection. The vulnerability exists it is possible to impersonate using an arbitrary user name if ACL is enabled, allowing an attacker to provide malicious input to build and execute a Unix shell command arbitrarily.