Skip to content

[GHSA-9437-39hj-3c93] There is a lack of XSS escaping in the Spark History Serv... - #10101

Draft
oscerd wants to merge 1 commit into
github:oscerd/advisory-improvement-10101from
oscerd:oscerd-GHSA-9437-39hj-3c93
Draft

oscerd wants to merge 1 commit into
github:oscerd/advisory-improvement-10101from
oscerd:oscerd-GHSA-9437-39hj-3c93

Conversation

@oscerd

@oscerd oscerd commented Oct 2, 2026

Copy link
Copy Markdown

[GHSA-9437-39hj-3c93] There is a lack of XSS escaping in the Spark History Serv...

Updates

  • Affected products
  • Source code location

Comments
Affected package, version range and source code location are taken from the official Apache Spark security advisory: https://lists.apache.org/thread/k36prh3oxl1z6ov7w8rpmfnt07hmzw3v

The advisory's "Affected versions" header states "Apache Spark (org.apache.spark:*) 3.0.0 before 3.5.8". The History Server lives in spark-core, so both published Scala variants are listed; spark-core_2.13 itself starts at 3.2.0, which the range simply subsumes. Tracked upstream as SPARK-53747.

Claude Code on behalf of oscerd

🤖 Generated with Claude Code

…story Serv...

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
@github-actions
github-actions Bot changed the base branch from main to oscerd/advisory-improvement-10101 October 2, 2026 08:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant