0.11.2
9 years ago
5 months ago
Known vulnerabilities in the org.apache.zeppelin:zeppelin package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Improper Input Validation in How to fix Improper Input Validation? Upgrade | [,0.10.0) |
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the markdown interpreter of Apache Zeppelin, which allows an attacker to inject malicious scripts. PoC
How to fix Cross-site Scripting (XSS)? Upgrade | [,0.10.0) |
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Command Injection. Bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. PoC
How to fix Command Injection? Upgrade | [,0.10.0) |
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Access Restriction Bypass. An Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. How to fix Access Restriction Bypass? Upgrade | [,0.10.0) |
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Session Fixation. This could allow an attacker to hijack a valid user session by sending a crafted URL with a predetermined session token to a victim which will then be accepted by the application during the victim's authentication. How to fix Session Fixation? Upgrade | [,0.7.3) |
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via Note permissions. How to fix Cross-site Scripting (XSS)? Upgrade | [,0.8.0) |
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Access Control Bypass. The cron scheduler enabled by default could allow users to run paragraphs as other users without authentication. How to fix Access Control Bypass? Upgrade | [,0.8.0) |