QID 980636
QID 980636: Java (maven) Security Update for org.apache.zeppelin:zeppelin (GHSA-87p2-cvhq-q4mv)
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-87p2-cvhq-q4mv for updates pertaining to this vulnerability.
Vendor References
- GHSA-87p2-cvhq-q4mv -
github.com/advisories/GHSA-87p2-cvhq-q4mv
CVEs related to QID 980636
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-87p2-cvhq-q4mv | org.apache.zeppelin:zeppelin |
|