CVE-2017-12619

CWE-3844 documents4 sources
Severity
8.1HIGH
EPSS
0.9%
top 23.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23
Latest updateApr 24

Description

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Session Fixation in Apache Zeppelin2019-04-24
OSV
Session Fixation in Apache Zeppelin2019-04-24
CVEList
CVE-2017-12619: Apache Zeppelin prior to 02019-04-23
CVE-2017-12619 (HIGH CVSS 8.1) | Apache Zeppelin prior to 0.7.3 was | cvebase.io