CVE-2021-27578

MEDIUM

Apache Zeppelin < 0.9.0 - Cross-Site Scripting in Markdown Interpreter

Title source: llm
STIX 2.1

Description

Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0.

Scores

CVSS v3 6.1
EPSS 0.0070
EPSS Percentile 72.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
apache/zeppelin < 0.9.0
org.apache.zeppelin/zeppelin 0 - 0.9.0Maven
Published Sep 02, 2021
Tracked Since Feb 18, 2026