QID 980638
QID 980638: Java (maven) Security Update for org.apache.zeppelin:zeppelin (GHSA-4qw8-pgpr-p9mq)
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4qw8-pgpr-p9mq for updates pertaining to this vulnerability.
Vendor References
- GHSA-4qw8-pgpr-p9mq -
github.com/advisories/GHSA-4qw8-pgpr-p9mq
CVEs related to QID 980638
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4qw8-pgpr-p9mq | org.apache.zeppelin:zeppelin |
|