Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Livy: Unauthorized directory access
Vulnerability Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnerability can only be exploited with non-default Apache Livy Server settings. If the configuration value "livy.file.local-dir-whitelist" is set to a non-default value, the directory checking can be bypassed. Users are recommended to upgrade to version 0.9.0, which fixes the issue.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Apache Livy 路径遍历漏洞
Vulnerability Description
Apache Livy是美国阿帕奇(Apache)基金会的一个应用服务器。提供支持从Web、移动应用程序以编程方式,容错,多租户提交Spark作业。 Apache Livy 0.9.0之前版本存在路径遍历漏洞,该漏洞源于路径名限制不当,可能导致路径遍历攻击,如果配置值livy.file.local-dir-whitelist设置为非默认值,则可以绕过目录检查。
CVSS Information
N/A
Vulnerability Type
N/A