Apache Software Foundation Apache Zeppelin vulnerabilities
23 known vulnerabilities affecting apache_software_foundation/apache_zeppelin.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM16
Vulnerabilities
Page 2 of 2
CVE-2024-41177P4MEDIUMCVSS 6.1fixed in 0.12.02025-08-03
CVE-2024-41177 [MEDIUM] CWE-79 CVE-2024-41177: Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects A
Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin.
This issue affects Apache Zeppelin: before 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue.
nvd
CVE-2022-46870P4MEDIUMCVSS 5.4fixed in 0.8.22022-12-16
CVE-2022-46870 [MEDIUM] CWE-79 CVE-2022-46870: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers.
This issue affects Apache Zeppelin before 0.8.2. Users are recommended to upgrade to a supported version of Zeppelin.
nvd
CVE-2021-28656P4MEDIUMCVSS 5.4≤ 0.9.02024-04-09
CVE-2021-28656 [MEDIUM] CWE-352 CVE-2021-28656: Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an atta
Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
nvd
← Previous2 / 2