Skip to content

apache livy exposed UI RCE#154

Open
joernNNN wants to merge 6 commits intogoogle:mainfrom
joernNNN:apache-livy-exposed-ui
Open

apache livy exposed UI RCE#154
joernNNN wants to merge 6 commits intogoogle:mainfrom
joernNNN:apache-livy-exposed-ui

Conversation

@joernNNN
Copy link
Contributor

@joernNNN joernNNN commented Aug 8, 2025

@giacomo-doyensec
Copy link
Contributor

Hello @joernNNN, could you please provide a hardened/secured version of the testbed along with the corresponding deployment instructions?

@joernNNN
Copy link
Contributor Author

joernNNN commented Oct 3, 2025

Hi @giacomo-doyensec, for a hardened version, can we put it behind a reverse HTTP proxy with basic authentication enabled?

@joernNNN
Copy link
Contributor Author

joernNNN commented Oct 9, 2025

@giacomo-doyensec, kindly pinging about the last question.

@giacomo-doyensec
Copy link
Contributor

Hi @joernNNN, if the software provides built-in hardening, please use that; it’s the preferred approach. If that’s not available or if full hardening would make the testbed unreasonably complex, feel free to use basic auth as a fallback.

@joernNNN
Copy link
Contributor Author

@robert-doyensec Hi
I've added a secure instance. Sorry for the delay.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants