Количество 2
Количество 2
CVE-2024-31868
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
GHSA-rrvf-5w4r-3x7v
Apache Zeppelin vulnerable to cross-site scripting in the helium module
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-31868 Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue. | CVSS3: 6.1 | 1% Низкий | почти 2 года назад | |
GHSA-rrvf-5w4r-3x7v Apache Zeppelin vulnerable to cross-site scripting in the helium module | CVSS3: 6.1 | 1% Низкий | почти 2 года назад |
Уязвимостей на страницу