Apache Zeppelin vulnerabilities
26 known vulnerabilities affecting apache/zeppelin.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM19
Vulnerabilities
Page 2 of 2
CVE-2024-31868P4MEDIUMCVSS 6.1≥ 0.8.2, < 0.11.12024-04-09
CVE-2024-31868 [MEDIUM] CWE-79 CVE-2024-31868: Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.
The attackers can modify helium.json and exposure XSS attacks to normal users.
This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
nvd
CVE-2024-31862P4MEDIUMCVSS 5.3≥ 0.10.1, < 0.11.02024-04-09
CVE-2024-31862 [MEDIUM] CWE-20 CVE-2024-31862: Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's
Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0.
Users are recommended to upgrade to version 0.11.0, which fixes the issue.
nvd
CVE-2024-52279P4MEDIUMCVSS 5.3≥ 0.11.1, < 0.12.02025-08-03
CVE-2024-52279 [MEDIUM] CVE-2024-52279: Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2
Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input.
This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue.
nvd
CVE-2024-41177P4MEDIUMCVSS 6.1fixed in 0.12.02025-08-03
CVE-2024-41177 [MEDIUM] CWE-79 CVE-2024-41177: Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects A
Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin.
This issue affects Apache Zeppelin: before 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue.
nvd
CVE-2022-46870P4MEDIUMCVSS 5.4fixed in 0.8.22022-12-16
CVE-2022-46870 [MEDIUM] CWE-79 CVE-2022-46870: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers.
This issue affects Apache Zeppelin before 0.8.2. Users are recommended to upgrade to a supported version of Zeppelin.
nvd
CVE-2021-28656P4MEDIUMCVSS 5.4≤ 0.9.02024-04-09
CVE-2021-28656 [MEDIUM] CWE-352 CVE-2021-28656: Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an atta
Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
nvd
← Previous2 / 2