Описание
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.
Ссылки
- Mailing ListRelease NotesThird Party Advisory
- Third Party AdvisoryVDB Entry
- Release NotesVendor Advisory
- Mailing ListRelease NotesThird Party Advisory
- Third Party AdvisoryVDB Entry
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.8.0 (исключая)
cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03414
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
EPSS
Процентиль: 87%
0.03414
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-287