CVE-2021-28655

MEDIUM

Apache Zeppelin < 0.9.0 - Arbitrary File Deletion via Move Folder to Trash Feature

Title source: llm
STIX 2.1

Description

The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

References (1)

Core 1
Core References
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/bxs056g3xlsofz0jb3wny9dw4llwptd2

Scores

CVSS v3 6.5
EPSS 0.0032
EPSS Percentile 55.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
apache/zeppelin < 0.9.0
org.apache.zeppelin/zeppelin 0 - 0.10.0Maven
Published Dec 16, 2022
Tracked Since Feb 18, 2026