Описание
Session Fixation in Apache Zeppelin
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
Пакеты
Наименование
org.apache.zeppelin:zeppelin
maven
Затронутые версииВерсия исправления
< 0.7.3
0.7.3
Связанные уязвимости
CVSS3: 8.1
nvd
почти 7 лет назад
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".