Apache Livy
cpe:2.3:a:apache:livy:*:*:*:*:*:*:*
- >= 0.3.0-incubating, < 0.9.0-incubating
A path traversal vulnerability has been identified in Apache Livy versions 0.3.0-incubating prior to 0.9.0-incubating. This vulnerability arises from improper restrictions on pathname limitations, allowing unauthorized access to directories. It can be exploited only under non-default Apache Livy Server configurations, specifically when the 'livy.file.local-dir-whitelist' value is set to a non-default option, bypassing the intended directory checks.
Exploitation of this vulnerability could lead to unauthorized access to restricted directories on the server.
Users are advised to upgrade to Apache Livy version 0.9.0, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.