PT-2022-9904 · Apache · Apache Zeppelin

Kai Zhao

·

Published

2022-12-16

·

Updated

2023-07-06

·

CVE-2021-28655

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache Zeppelin versions 0.9.0 and prior versions
Description The issue is related to improper Input Validation in the "Move folder to Trash" feature of Apache Zeppelin, allowing an attacker to delete arbitrary files.
Recommendations For Apache Zeppelin versions 0.9.0 and prior, consider disabling the "Move folder to Trash" feature until a patch is available to prevent arbitrary file deletion.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-28655
GHSA-GM67-H5WR-W3CV

Affected Products

Apache Zeppelin