CVE-2021-27578
MEDIUMApache Zeppelin < 0.9.0 - Cross-Site Scripting in Markdown Interpreter
Title source: llmDescription
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0.
References (5)
Core 5
Core References
Mailing List, Vendor Advisory mailing-list
https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b06707b38da4cb3d%40%3Cusers.zeppelin.apache.org%3E
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2021/09/02/3
Mailing List mailing-list
https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b06707b38da4cb3d%40%3Cannounce.apache.org%3E
Mailing List mailing-list
https://lists.apache.org/thread.html/r31012f2c8e39a5e12e14c1de030012cb8b51c037d953d73b291b7b50%40%3Cusers.zeppelin.apache.org%3E
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202311-04
Scores
CVSS v3
6.1
EPSS
0.0070
EPSS Percentile
72.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
apache/zeppelin
< 0.9.0
org.apache.zeppelin/zeppelin
0 - 0.9.0Maven
Published
Sep 02, 2021
Tracked Since
Feb 18, 2026