© 2025-2026 PySpect
First version without a known vulnerability: 4.0.0.dev1
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later.
Fixed in: 3.5.8
Apache Spark has Inadequate Encryption Strength
Fixed in: 3.5.2, 3.4.4
Apache Spark UI vulnerable to Command Injection
Fixed in: 3.2.2
Apache Spark vulnerable to Improper Privilege Management
Fixed in: 3.3.3, 3.3.2, 3.4.0
Apache Spark vulnerable to Log Injection
Fixed in: 3.2.2, 3.3.1
Apache Spark UI can allow impersonation if ACLs enabled
Fixed in: 3.2.2, 3.1.3
Authentication Bypass by Capture-replay in Apache Spark
Fixed in: 3.1.3
Improper Authentication in Apache Spark
Fixed in: 2.4.6
Sensitive data written to disk unencrypted in Spark
Fixed in: 2.3.3
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
Fixed in: 2.1.3, 2.2.2, 2.3.1
Pyspark User Impersonation Vulnerability
Fixed in: 2.3.2, 2.2.3
Apache Spark Deserialization of Untrusted Data vulnerability
Fixed in: 2.1.2