Description
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
References (5)
Core 5
Core References
Mailing List, Vendor Advisory mailing-list
https://lists.apache.org/thread.html/rdf06e8423833b3daadc30c56a2ff47c48920864d5199476daa897208%40%3Cusers.zeppelin.apache.org%3E
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2021/09/02/1
Mailing List mailing-list
https://lists.apache.org/thread.html/rdf06e8423833b3daadc30c56a2ff47c48920864d5199476daa897208%40%3Cannounce.apache.org%3E
Mailing List mailing-list
https://lists.apache.org/thread.html/rd56389ba9cab30a6c976b9a4a6df0f85cbe8fba6a60a3cf6e3ba716b%40%3Cusers.zeppelin.apache.org%3E
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202311-04
Scores
CVSS v3
9.8
EPSS
0.0302
EPSS Percentile
86.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (2)
apache/zeppelin
< 0.9.0
org.apache.zeppelin/zeppelin
0 - 0.10.0Maven
Published
Sep 02, 2021
Tracked Since
Feb 18, 2026