VYPR

Maven package

org.apache.spark/spark-core_2.9.3

pkg:maven/org.apache.spark/spark-core_2.9.3

Vulnerabilities (2)

  • CVE-2025-54920Mar 14, 2026
    affected <= 0.8.1-incubating

    This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to ov

  • CVE-2022-31777Nov 1, 2022
    affected >= 0

    A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.