CVE-2025-60012

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
13/03/2026
Last modified:
13/03/2026

Description

Malicious configuration can lead to unauthorized file access in Apache Livy.<br /> <br /> This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later.<br /> <br /> A request that includes a Spark configuration value supported from Apache Spark version 3.1 can lead to users gaining access to files they do not have permissions to.<br /> <br /> For the vulnerability to be exploitable, the user needs to have access to Apache Livy&amp;#39;s REST or JDBC interface and be able to send requests with arbitrary Spark configuration values.<br /> <br /> Users are recommended to upgrade to version 0.9.0 or later, which fixes the issue.