{"id":"CVE-2017-7678","aliases":["GHSA-r34r-f84j-5x4x"],"url":"https://o3.security/vulnerability/CVE-2017-7678","summary":"Moderate severity vulnerability that affects org.apache.spark:spark-core_2.10 and org.apache.spark:spark-core_2.11","details":"In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits data including MHTML to the Spark master, or history server. This data, which could contain a script, would then be reflected back to the user and could be evaluated and executed by MS Windows-based clients. It is not an attack on Spark itself, but on the user, who may then execute the script inadvertently when viewing elements of the Spark web UIs.","published":"2017-07-12T13:29:00.267Z","modified":"2026-07-08T16:53:43.994853Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.spark:spark-core_2.11","fixedVersion":"2.2.0"},{"ecosystem":"Maven","name":"org.apache.spark:spark-core_2.10","fixedVersion":"2.2.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://apache-spark-developers-list.1001551.n3.nabble.com/CVE-2017-7678-Apache-Spark-XSS-web-UI-MHTML-vulnerability-td21947.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/99603"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:53:43.994853Z"}}