Description
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
References (5)
Core 5
Core References
Mailing List, Vendor Advisory mailing-list
https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cusers.zeppelin.apache.org%3E
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2021/09/02/2
Mailing List mailing-list
https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cannounce.apache.org%3E
Mailing List mailing-list
https://lists.apache.org/thread.html/r99529e175a7c1c9a26bd41a02802c8af7aa97319fe561874627eb999%40%3Cusers.zeppelin.apache.org%3E
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202311-04
Scores
CVSS v3
7.5
EPSS
0.0012
EPSS Percentile
31.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
Status
published
Products (2)
apache/zeppelin
< 0.9.0
org.apache.zeppelin/zeppelin
0 - 0.10.0Maven
Published
Sep 02, 2021
Tracked Since
Feb 18, 2026