Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1nbTY3LWg1d3ItdzNjds4AA0Ts
Apache Zeppelin Improper Input Validation vulnerability
The improper Input Validation vulnerability in Move folder to Trash
feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nbTY3LWg1d3ItdzNjds4AA0Ts
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 5 months ago
Updated: 5 months ago
CVSS Score: 6.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Identifiers: GHSA-gm67-h5wr-w3cv, CVE-2021-28655
References:
- https://nvd.nist.gov/vuln/detail/CVE-2021-28655
- https://lists.apache.org/thread/bxs056g3xlsofz0jb3wny9dw4llwptd2
- https://github.com/advisories/GHSA-gm67-h5wr-w3cv
Affected Packages
maven:org.apache.zeppelin:zeppelin
Versions: < 0.10.0Fixed in: 0.10.0