PT-2021-8864 · Apache · Apache Zeppelin

Published

2021-09-02

·

Updated

2023-11-24

·

CVE-2019-10095

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Zeppelin versions 0.9.0 and prior versions
Description A bash command injection issue in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings.
Recommendations For Apache Zeppelin versions 0.9.0 and prior, consider restricting access to the Spark interpreter settings to minimize the risk of exploitation until a fix is available.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2019-10095
GHSA-4QW8-PGPR-P9MQ

Affected Products

Apache Zeppelin