Описание
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy 0.7.1-incubating.
Ссылки
- Mailing ListPatchThird Party Advisory
- PatchThird Party Advisory
- PatchVendor Advisory
- Mailing ListPatchThird Party Advisory
- PatchThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:apache:livy:0.7.0-incubating:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02403
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
больше 4 лет назад
Apache Livy Cross-site scripting (XSS) in session names
EPSS
Процентиль: 85%
0.02403
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
CWE-79