CVE-2025-60012
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
13/03/2026
Last modified:
13/03/2026
Description
Malicious configuration can lead to unauthorized file access in Apache Livy.<br />
<br />
This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later.<br />
<br />
A request that includes a Spark configuration value supported from Apache Spark version 3.1 can lead to users gaining access to files they do not have permissions to.<br />
<br />
For the vulnerability to be exploitable, the user needs to have access to Apache Livy&#39;s REST or JDBC interface and be able to send requests with arbitrary Spark configuration values.<br />
<br />
Users are recommended to upgrade to version 0.9.0 or later, which fixes the issue.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM



