CVE-2025-60012Disclosure(apache / livy)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache livy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later. A request that includes a Spark configuration value supported from Apache Spark version 3.1 can lead to users gaining access to files they do not have permissions to. For the vulnerability to be exploitable, the user needs to have access to Apache Livy's REST or JDBC interface and be able to send requests with arbitrary Spark configuration values. Users are recommended to upgrade to version 0.9.0 or later, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • livy

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-13); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
livy

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-12: 1Mentions · 2026-03-13: 2Mentions · 2026-03-14: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 2Technical Details · 2026-03-14: 103-1203-1303-14
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-132
General1Patch1
2026-03-141
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2025-60012: Apache Livy: Malicious configuration can lead to unauthorized file access https://www.openwall.com/lists/oss-security/2026/03/12/1 CVE-2025-66249: Apache Livy: Unauthorized directory access (path traversal) https://www.openwall.com/lists/oss-security/2026/03/12/2 Both are "Severity: important"

    Post summary

    The text announces two new Apache Livy CVEs, describing the nature of the vulnerabilities (unauthorized file and directory access) and noting their importance, without providing PoCs, exploits, or patch details.

    00020396
    4.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Protect your Spark clusters: Apache Livy 0.9.0 patches two important file access and path traversal vulnerabilities (CVE-2025-60012 & CVE-2025-66249). https://securityonline.info/apache-livy-patches-path-traversal-and-file-access-flaws-exposing-spark-clusters/ https://t.co/S1LvIRHlxY

    Post summary

    Apache Livy 0.9.0 releases a patch addressing file access and path traversal flaws (CVE‑2025‑60012 & CVE‑2025‑66249), but no exploitation details or PoC are provided.

    00001310
    10.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-60012 Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or la… https://www.cve.org/CVERecord?id=CVE-2025-60012

    Post summary

    The note reports CVE‑2025‑60012, a misconfiguration in Apache Livy that can enable unauthorized file access on specific versions; no PoC or exploit details are given.

    00000164
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-60012 - Apache Livy Spark Configuration File Access Vulnerability Intel Report: https://ift.tt/5kNcem7

    Post summary

    A threat alert references CVE-2025-60012, an Apache Livy Spark configuration file access vulnerability, but provides no PoC, exploit, active exploitation, or patch details.

    00000185
    340 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachelivy---

Explore more