CVE-2025-60012
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-20
Validación incorrecta de entrada
Fecha de publicación:
13/03/2026
Última modificación:
13/03/2026
Descripción
*** Pendiente de traducción *** Malicious configuration can lead to unauthorized file access in Apache Livy.<br />
<br />
This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later.<br />
<br />
A request that includes a Spark configuration value supported from Apache Spark version 3.1 can lead to users gaining access to files they do not have permissions to.<br />
<br />
For the vulnerability to be exploitable, the user needs to have access to Apache Livy&#39;s REST or JDBC interface and be able to send requests with arbitrary Spark configuration values.<br />
<br />
Users are recommended to upgrade to version 0.9.0 or later, which fixes the issue.
Impacto
Puntuación base 3.x
6.30
Gravedad 3.x
MEDIA



