0.11.2
9 years ago
5 months ago
Known vulnerabilities in the org.apache.zeppelin:zeppelin package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Improper Input Validation in How to fix Improper Input Validation? Upgrade | [,0.10.0) |
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the markdown interpreter of Apache Zeppelin, which allows an attacker to inject malicious scripts. PoC
How to fix Cross-site Scripting (XSS)? Upgrade | [,0.10.0) |
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Command Injection. Bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. PoC
How to fix Command Injection? Upgrade | [,0.10.0) |
org.apache.zeppelin:zeppelin is a web-based notebook that enables interactive data analytics. Affected versions of this package are vulnerable to Access Restriction Bypass. An Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. How to fix Access Restriction Bypass? Upgrade | [,0.10.0) |