Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9p8j-hrgf-jc2g

Опубликовано: 20 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Apache Zeppelin Cross-site Scripting vulnerability

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. Users are recommended to upgrade to a supported version of Zeppelin.

Пакеты

Наименование

org.apache.zeppelin:zeppelin

maven
Затронутые версииВерсия исправления

< 0.8.2

0.8.2

EPSS

Процентиль: 94%
0.1289
Средний

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. Users are recommended to upgrade to a supported version of Zeppelin.

EPSS

Процентиль: 94%
0.1289
Средний

5.4 Medium

CVSS3

Дефекты

CWE-79