Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-74qp-233x-p5j8

Опубликовано: 13 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Apache Livy Cross-site scripting (XSS) in session names

Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy 0.7.1-incubating.

Пакеты

Наименование

org.apache.livy:livy-server

maven
Затронутые версииВерсия исправления

= 0.7.0-incubating

0.7.1-incubating

EPSS

Процентиль: 85%
0.02403
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 5 лет назад

Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy 0.7.1-incubating.

EPSS

Процентиль: 85%
0.02403
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79