Skip to main content

Vendor/product archive

apache / livy CVEs

Beta · best-effort

3 CVEs tagged to apache / livy0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-66249

Published Mar 13, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnera…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60012

Published Mar 13, 2026

Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later. A reque…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26544

Published Feb 20, 2021

Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of o…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1