bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Zeppelin
APPApache≤ 0.9.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2024-31864CRITICAL9.8PL ✓same product
Apache Zeppelin: Code Injection przez JDBC przy połączeniu z MySQL
CVE-2024-31866CRITICAL9.8PL ✓same product
Apache Zeppelin — wykonanie kodu przez nieprawidłowe kodowanie konfiguracji
CVE-2024-41169HIGH7.5same product
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's res...
CVE-2020-13929HIGH7.5same product
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication me...
CVE-2017-12619HIGH8.1same product
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid ...