CVE-2020-13929
Summary
| CVE | CVE-2020-13929 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-02 17:15:00 UTC |
| Updated | 2023-11-24 14:15:00 UTC |
| Description | Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [zeppelin-users] 20210928 Re: CVE-2020-13929: Apache Zeppelin: Notebook permissions bypass | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MISC | lists.apache.org | |
| oss-security - CVE-2020-13929: Apache Zeppelin: Notebook permissions bypass | MLIST | www.openwall.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Zeppelin: Multiple Vulnerabilities (GLSA 202311-04) — Gentoo security | security.gentoo.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Apache Zeppelin would like to thank David Woodhouse for reporting this issue