PT-2026-25061 · Apache · Apache Ivy+1
Furue Hideyuki
·
Published
2026-03-12
·
Updated
2026-03-14
·
CVE-2025-60012
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Apache Livy versions 0.7.0 and 0.8.0
Description
A malicious configuration can lead to unauthorized file access in Apache Livy. This issue occurs when connecting to Apache Spark 3.1 or later. A request including a Spark configuration value supported from Apache Spark version 3.1 can allow users to gain access to files they are not permitted to access. Exploitation requires access to the Apache Livy REST or JDBC interface and the ability to send requests with arbitrary Spark configuration values. The vulnerable component is the Spark configuration processing logic within Apache Livy.
Recommendations
Upgrade to version 0.9.0 or later to resolve this issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Ivy
Apache Spark