VYPR

Livy

by Apache

Source repositories

CVEs (3)

  • CVE-2025-66249MedMar 13, 2026
    risk 0.34cvss 6.3epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnerability can only be exploited with non-default Apache Livy Server settings. If the configuration…

  • CVE-2025-60012MedMar 13, 2026
    risk 0.34cvss 6.3epss 0.00

    Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later. A request that includes a Spark configuration value supported from Apache Spark version 3.1 can lead to…

  • CVE-2021-26544MedFeb 20, 2021
    risk 0.28cvss 5.4epss 0.03

    Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy…