PT-2019-8927 · Apache · Apache Zeppelin

Published

2019-04-23

·

Updated

2019-04-30

·

CVE-2018-1317

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Zeppelin versions prior to 0.8.0
Description The issue allows users to run paragraphs as other users without authentication due to the cron scheduler being enabled by default.
Recommendations For versions prior to 0.8.0, update to version 0.8.0 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1317
GHSA-9X2H-HVG6-4R5P

Affected Products

Apache Zeppelin