Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g44m-x5h7-fr5q

Опубликовано: 09 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Apache Zeppelin: Cron arbitrary user impersonation with improper privileges

Improper Input Validation vulnerability in Apache Zeppelin.

The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges.

This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.

Users are recommended to upgrade to version 0.11.1, which fixes the issue.

Пакеты

Наименование

org.apache.zeppelin:zeppelin-server

maven
Затронутые версииВерсия исправления

>= 0.8.2, < 0.11.1

0.11.1

EPSS

Процентиль: 70%
0.00631
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-20
CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.

EPSS

Процентиль: 70%
0.00631
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-20
CWE-862