Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-60012

Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-20 Validación incorrecta de entrada
Fecha de publicación:
13/03/2026
Última modificación:
13/03/2026

Descripción

*** Pendiente de traducción *** Malicious configuration can lead to unauthorized file access in Apache Livy.<br /> <br /> This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later.<br /> <br /> A request that includes a Spark configuration value supported from Apache Spark version 3.1 can lead to users gaining access to files they do not have permissions to.<br /> <br /> For the vulnerability to be exploitable, the user needs to have access to Apache Livy&amp;#39;s REST or JDBC interface and be able to send requests with arbitrary Spark configuration values.<br /> <br /> Users are recommended to upgrade to version 0.9.0 or later, which fixes the issue.