Apache Spark Command Injection Vulnerability
Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
CISA entryApache · AUTOMATIC DISCOVERY
Apache Spark is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.
Apache Spark is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Used to provide application, infrastructure or operational services to other systems and users.
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
| Product | Apache Spark |
|---|---|
| Release | Product policy |
| End of Support | March 2027 |
| Date precision | Quarter |
These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
CISA entryOSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
The calendar below is an example to show how the community expects to bootstrap the faster cadence; exact dates stay subject to the usual release-discussion and voting process. | 2026 : Ship Apache Spark 4.2.0 on the timeline above (the last large feature drop before the transition). 4.2.x is not affected by this policy (development began before the SPIP); existing commitments, including the 18 -month maintenance window for 4.2.x , are unchanged. After 4.2.0 is generally available, plan Apache Spark 4.3.0 as the first quarterly feature release on the new train (for example, roughly three months after the 4.2.0 GA date for the start of the 4.3 merge/RC cycle—this is not a fixed rule, only an illustration of quarterly feature releases). | 2027 : Ship Apache Spark 5.0.0 as the next annual major. Follow with quarterly 5.1.0 , 5.2.0 , and 5.3.0 feature releases; 5.3.0 is the 5.x LTS as the last 5.x feature release (for example targeting calendar quarters 2027 Q1 through Q4 if the 5.0.0 major lands early in the year). | Maintenance releases and EOL | We plan to ship a release every 3 months. Every fourth release bumps the major version ( x.0.0 ). Within each major line, the first release is the major release, the releases in between are feature releases, and the last release in the line is the LTS release. | The following table summarizes the maintenance window for each release type: | Release branches other than LTS will, generally, be maintained with bug fix releases for a period of 6 months (see the Major and Feature rows in the table above).
Publisher identity used by product-specific official-source collectors.
Open official vendor source