0.12.1
10 years ago
2 months ago
Known vulnerabilities in the org.apache.zeppelin:zeppelin-server package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.apache.zeppelin:zeppelin-server is a web-based notebook that enables interactive data analytics. You can make beautiful data-driven, interactive and collaborative documents with SQL, Scala and more. Affected versions of this package are vulnerable to Directory Traversal through the How to fix Directory Traversal? Upgrade | [0.9.0,0.12.1) |
org.apache.zeppelin:zeppelin-server is a web-based notebook that enables interactive data analytics. You can make beautiful data-driven, interactive and collaborative documents with SQL, Scala and more. Affected versions of this package are vulnerable to LDAP Injection through the How to fix LDAP Injection? Upgrade | [0.6.0,0.12.1) |
org.apache.zeppelin:zeppelin-server is a web-based notebook that enables interactive data analytics. You can make beautiful data-driven, interactive and collaborative documents with SQL, Scala and more. Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) through the REST and WebSocket request-handling layer in How to fix Cross-site Request Forgery (CSRF)? Upgrade | [0.6.0,0.12.1) |
org.apache.zeppelin:zeppelin-server is a web-based notebook that enables interactive data analytics. You can make beautiful data-driven, interactive and collaborative documents with SQL, Scala and more. Affected versions of this package are vulnerable to Improper Input Validation due to the improper handling of updating cron API with invalid or improper privileges, allowing the notebook to run with elevated privileges. This vulnerability can be exploited by attackers to escalate their privileges and potentially gain unauthorized access or perform unauthorized actions. How to fix Improper Input Validation? Upgrade | [0.8.2,0.11.1) |
org.apache.zeppelin:zeppelin-server is a web-based notebook that enables interactive data analytics. You can make beautiful data-driven, interactive and collaborative documents with SQL, Scala and more. Affected versions of this package are vulnerable to LDAP Injection due to improper configuration properties set for the LDAP search filter. An attacker can execute malicious queries by setting these improper configurations. How to fix LDAP Injection? Upgrade | [0.8.2,0.11.1) |
org.apache.zeppelin:zeppelin-server is a web-based notebook that enables interactive data analytics. You can make beautiful data-driven, interactive and collaborative documents with SQL, Scala and more. Affected versions of this package are vulnerable to Path Traversal due to improper input validation. An attacker can view the contents of any files in the filesystem that the server account can access by adding relative path indicators (e.g How to fix Path Traversal? Upgrade | [0.9.0,0.11.0) |
org.apache.zeppelin:zeppelin-server is a web-based notebook that enables interactive data analytics. You can make beautiful data-driven, interactive and collaborative documents with SQL, Scala and more. Affected versions of this package are vulnerable to SQL Injection via the How to fix SQL Injection? Upgrade | [0.8.0,0.11.0) |