已开启
CVE-2023-22946 #31
openeuler-ci-bot创建于  2023年4月17日
openeuler-ci-bot
openeuler-ci-bot成员
2023年4月17日 创建

一、漏洞信息
漏洞编号:CVE-2023-22946
漏洞归属组件:spark
漏洞归属的版本:3.0.1,3.2.0,3.2.2,3.5.0
CVSS评分:
BaseScore:9.9 Critical
Vector:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
漏洞简述:
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a proxy-user to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however, by providing malicious configuration-related classes on the classpath. This affects architectures relying on proxy-user, for example those using Apache Livy to manage submitted applications.Update to Apache Spark 3.4.0 or later, and ensure that spark.submit.proxyUser.allowCustomClasspathInClusterMode is set to its default of false , and is not overridden by submitted applications.
漏洞公开时间:2023-04-17 16:15:07
漏洞创建时间:2025-10-27 19:09:30
漏洞详情参考链接:
https://nvd.nist.gov/vuln/detail/CVE-2023-22946

更多参考(点击展开)
参考来源 参考链接 来源链接
security.apache.org https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv
suse_bugzilla http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-22946 https://bugzilla.suse.com/show_bug.cgi?id=1210504
suse_bugzilla https://seclists.org/oss-sec/2023/q2/28 https://bugzilla.suse.com/show_bug.cgi?id=1210504
debian https://security-tracker.debian.org/tracker/CVE-2023-22946
trousers https://spark.apache.org/ https://seclists.org/oss-sec/2023/q2/28
trousers https://www.cve.org/CVERecord?id=CVE-2023-22946 https://seclists.org/oss-sec/2023/q2/28
trousers https://issues.apache.org/jira/browse/SPARK-41958 https://seclists.org/oss-sec/2023/q2/28
oracle https://www.oracle.com/security-alerts/cpuoct2023.html
cve_search https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv
github_advisory https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv https://github.com/advisories/GHSA-329j-jfvr-rhr6
github_advisory https://nvd.nist.gov/vuln/detail/CVE-2023-22946 https://github.com/advisories/GHSA-329j-jfvr-rhr6
osv https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv https://osv.dev/vulnerability/CVE-2023-22946
snyk https://issues.apache.org/jira/browse/SPARK-41958 https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHESPARK-5425123
snyk https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHESPARK-5425123
snyk https://github.com/apache/spark/commit/909da96e1471886a01a9e1def93630c4fd40e74a https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHESPARK-5425123
snyk https://github.com/apache/spark/pull/39474 https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHESPARK-5425123
snyk https://issues.apache.org/jira/browse/SPARK-41958 https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHESPARK-5425124
snyk https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHESPARK-5425124
snyk https://github.com/apache/spark/commit/909da96e1471886a01a9e1def93630c4fd40e74a https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHESPARK-5425124
snyk https://github.com/apache/spark/pull/39474 https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHESPARK-5425124
nvd https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv
redhat https://access.redhat.com/security/cve/CVE-2023-22946
osv https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv https://osv.dev/vulnerability/PYSEC-2023-44
nvd https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv

漏洞分析指导链接:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md
漏洞数据来源:
openBrain开源漏洞感知系统
漏洞补丁信息:

详情(点击展开)
影响的包 修复版本 修复补丁 问题引入补丁 来源
https://github.com/apache/spark/commit/909da96e1471886a01a9e1def93630c4fd40e74a snyk
https://github.com/apache/spark/pull/39474 snyk
https://lists.apache.org/thread/yllfl25xh5tbotjmg93zrq4bzwhqc0gv nvd

二、漏洞分析结构反馈
影响性分析说明:

openEuler评分:
9.9
Vector:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
受影响版本排查(受影响/不受影响):
1.master(3.5.0):
2.openEuler-20.03-LTS-SP4(3.2.0):
3.openEuler-22.03-LTS-Next(3.2.2):
4.openEuler-22.03-LTS-SP1(3.2.2):
5.openEuler-22.03-LTS-SP3(3.2.2):
6.openEuler-22.03-LTS-SP4(3.2.2):
7.openEuler-24.03-LTS(3.5.0):
8.openEuler-24.03-LTS-Next(3.5.0):

修复是否涉及abi变化(是/否):
1.master(3.5.0):
2.openEuler-20.03-LTS-SP4(3.2.0):
3.openEuler-22.03-LTS-SP3(3.2.2):
4.openEuler-22.03-LTS-SP4(3.2.2):
5.openEuler-24.03-LTS(3.5.0):
6.openEuler-24.03-LTS-Next(3.5.0):
7.openEuler-24.03-LTS-SP1(3.5.0):
8.openEuler-24.03-LTS-SP2(3.5.0):
9.openEuler-24.03-LTS-SP3(3.5.0):

原因说明:
1.master(3.5.0):
2.openEuler-20.03-LTS-SP4(3.2.0):
3.openEuler-22.03-LTS-SP4(3.2.2):
4.openEuler-24.03-LTS(3.5.0):
5.openEuler-24.03-LTS-Next(3.5.0):
6.openEuler-24.03-LTS-SP1(3.5.0):
7.openEuler-24.03-LTS-SP2(3.5.0):
8.openEuler-24.03-LTS-SP3(3.5.0):

likedislike
openeuler-ci-bot
openeuler-ci-bot成员
2023年4月17日 评论:

Hi openeuler-ci-bot, welcome to the openEuler Community.
I'm the Bot here serving you. You can find the instructions on how to interact with me at Here.
If you have any questions, please contact the SIG: bigdata, and any of the maintainers: @yangzhao_kl , @wuzeyi1 , @macchen1 , @my_code_x

likedislike
openeuler-ci-botopeneuler-ci-bot成员
2024年8月10日 修改了描述
openeuler-ci-botopeneuler-ci-bot成员
2024年8月11日 修改了描述
openeuler-ci-botopeneuler-ci-bot成员
2024年8月12日 修改了描述
openeuler-ci-botopeneuler-ci-bot成员
2024年8月14日 修改了描述
此处折叠了779条消息 查看更多
openeuler-ci-botopeneuler-ci-bot成员
1月3日 将 macchen1 设为负责人,移除负责人 yangzhao_kl
openeuler-ci-botopeneuler-ci-bot成员
1月7日 修改了issue 的描述
openeuler-ci-botopeneuler-ci-bot成员
1月20日 修改了issue 的描述
Cchenyanpan
8月17日 关联了pull request:Fix CVE-2022-31777, CVE-2023-22946, CVE-2023-32007, CVE-2025-54920, CVE-2025-55039
Cchenyanpan
8月24日 关联了pull request:Fix CVE-2022-31777, CVE-2023-22946, CVE-2023-32007, CVE-2025-55039