QID 730205
Date Published: 2021-09-23
QID 730205: Apache Zeppelin Multiple Vulnerabilities
Apache Zeppelin is a web-based notebook that enables data-driven, interactive data analytics and collaborative documents with SQL, Scala, Python, R and more.
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0.
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Affected Versions:
Apache Zeppelin version 0.9.0 and prior.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Apache Zeppelin by sending a GET request to /api/version endpoint .
Successful exploitation of the vulnerability may lead to complete system compromise
- Apache Zeppelin Security Advisory -
lists.apache.org/thread.html/rdf06e8423833b3daadc30c56a2ff47c48920864d5199476daa897208@%3Cannounce.apache.org%3E
CVEs related to QID 730205
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|