GHSA-74qp-233x-p5j8

    Dashboard / Vulnerabilities / GHSA-74qp-233x-p5j8

    GHSA-74qp-233x-p5j8

    Published: 13 May 2021Last Modified: 8 Nov 2023

    Summary: Apache Livy Cross-site scripting (XSS) in session names

    Details: Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy 0.7.1-incubating.

    Affected packages

    Package

    Name: org.apache.livy:livy-server

    Purl: pkg:maven/org.apache.livy/livy-server

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0.7.0-incubating
    Fixed -0.7.1-incubating

    Affected versions

    0.7.0-incubating

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-74qp-233x-p5j8 | CVE-DB