CVE-2018-1317

Severity
8.8HIGH
EPSS
3.3%
top 12.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23
Latest updateApr 24

Description

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Improper Authentication in Apache Zeppelin2019-04-24
OSV
Improper Authentication in Apache Zeppelin2019-04-24
CVEList
CVE-2018-1317: In Apache Zeppelin prior to 02019-04-23
CVE-2018-1317 (HIGH CVSS 8.8) | In Apache Zeppelin prior to 0.8.0 t | cvebase.io