Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NApache Zeppelin
APPApache≤ 0.9.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
References
Related vulnerabilities
CVE-2024-31866CRITICAL9.8PL ✓same product
Apache Zeppelin — wykonanie kodu przez nieprawidłowe kodowanie konfiguracji
CVE-2024-31864CRITICAL9.8PL ✓same product
Apache Zeppelin: Code Injection przez JDBC przy połączeniu z MySQL
CVE-2019-10095CRITICAL9.8PL ✓same product
Command injection w Apache Zeppelin — wstrzyknięcie poleceń bash
CVE-2024-41169HIGH7.5same product
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's res...
CVE-2017-12619HIGH8.1same product
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid ...