org.apache.livy:livy-server
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.livy:livy-serverpage 1 of 1
- CVE-2021-26544MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.7.1-incubating2021-02-20
vulnerable: 0.7.0-incubating
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. Thi…
- CVE-2025-60012MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.9.0-incubating2026-03-13
vulnerable: 0.7.0-incubating, 0.7.1-incubating, 0.8.0-incubating
Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later. A request that includes a Spark configuration value supported from…
- CVE-2025-66249MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.9.0-incubating2026-03-13
vulnerable: 0.4.0-incubating ... 0.8.0-incubating (6 versions)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnerability can only be exploited with non-default Apache Livy Se…
Check whether org.apache.livy:livy-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.livy:livy-server CVEs against the assets you own.
Start Free Scan →