CVE-2019-10095

CRITICAL

Apache Zeppelin <0.9.0 - Command Injection

Title source: llm
STIX 2.1

Description

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

Scores

CVSS v3 9.8
EPSS 0.0302
EPSS Percentile 86.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (2)
apache/zeppelin < 0.9.0
org.apache.zeppelin/zeppelin 0 - 0.10.0Maven
Published Sep 02, 2021
Tracked Since Feb 18, 2026