CVE-2020-13929

HIGH

Apache Zeppelin < 0.9.0 - Authentication Bypass

Title source: llm
STIX 2.1

Description

Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

Scores

CVSS v3 7.5
EPSS 0.0012
EPSS Percentile 31.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (2)
apache/zeppelin < 0.9.0
org.apache.zeppelin/zeppelin 0 - 0.10.0Maven
Published Sep 02, 2021
Tracked Since Feb 18, 2026