PT-2026-25062 · Apache · Apache Ivy

Hiroki Egawa

·

Publicado

2026-03-12

·

Atualizado

2026-03-14

·

CVE-2025-66249

CVSS v3.1

6.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache Livy versions 0.3.0 through 0.8.9
Description An improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in Apache Livy. This issue can be exploited with non-default Apache Livy Server settings. Specifically, if the livy.file.local-dir-whitelist configuration value is set to a non-default value, the directory checking can be bypassed.
Recommendations Upgrade to version 0.9.0 to resolve this issue.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66249
GHSA-H84F-4FF9-8HC3

Produtos afetados

Apache Ivy