Org.apache.zeppelin:zeppelin
This hub aggregates every CVE we track for Org.apache.zeppelin:zeppelin, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
1
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM4HIGH3CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 8 most recently published vulnerabilities affecting Org.apache.zeppelin:zeppelin.
- CVE-2022-46870Apache Zeppelin: Stored XSS in note permissions5.4
- CVE-2021-28655Apache Zeppelin: Arbitrary file deletion vulnerability6.5
- CVE-2021-27578Cross Site Scripting in markdown interpreter6.1
- CVE-2020-13929Notebook permissions bypass7.5
- CVE-2019-10095bash command injection in spark interpreter9.8
- CVE-2018-1328Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".6.1
- CVE-2018-1317In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.8.8
- CVE-2017-12619Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".8.1
Product normalization is registry-driven with AI assist and human review. How it works