Back to search
CVE-2021-26544
Published: Feb 20, 2021
Modified: Feb 13, 2025
PUBLISHED
Description
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy 0.7.1-incubating.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Livy (Incubating) | affected Apache Livy (Incubating) 0.7.0-incubating |
Weaknesses (CWE)
References
[oss-security] 20210220 CVE-2021-26544: Apache Livy (Incubating) is vulnerable to cross site scripting
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now