Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g64r-xf39-q4p5

Опубликовано: 09 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Apache Zeppelin Path Traversal vulnerability

Improper Input Validation vulnerability in Apache Zeppelin.

By adding relative path indicators (e.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin from 0.9.0 before 0.11.0.

Users are recommended to upgrade to version 0.11.0, which fixes the issue.

Пакеты

Наименование

org.apache.zeppelin:zeppelin-server

maven
Затронутые версииВерсия исправления

>= 0.9.0, < 0.11.0

0.11.0

EPSS

Процентиль: 72%
0.00732
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20
CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

EPSS

Процентиль: 72%
0.00732
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20
CWE-22