Apache Zeppelin vulnerabilities
22 known vulnerabilities affecting apache/zeppelin.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM15
Vulnerabilities
Page 2 of 2
CVE-2022-46870P4MEDIUMCVSS 5.4fixed in 0.8.22022-12-16
CVE-2022-46870 [MEDIUM] CWE-79 CVE-2022-46870: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers.
This issue affects Apache Zeppelin before 0.8.2. Users are recommended to upgrade to a supported version of Zeppelin.
nvd
CVE-2021-28656P4MEDIUMCVSS 5.4≤ 0.9.02024-04-09
CVE-2021-28656 [MEDIUM] CWE-352 CVE-2021-28656: Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an atta
Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
nvd
← Previous2 / 2