Apache Zeppelin
Apache · 25 CVEs
Path traversal in NotebookRepo note and folder path composition
Jul 31, 2026
Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
Jul 30, 2026
Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Jul 30, 2026
Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
Jul 30, 2026
Apache Zeppelin: Command Injection via CSWSH
Aug 3, 2025
Apache Zeppelin: XSS in the Helium module
Aug 3, 2025
Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string
Aug 3, 2025
Apache Zeppelin: raft directory listing and file read
Jul 12, 2025
Apache Zeppelin: LDAP search filter query Injection Vulnerability
Apr 9, 2024
Apache Zeppelin: XSS vulnerability in the helium module
Apr 9, 2024
Apache Zeppelin: Interpreter download command does not escape malicious code injection
Apr 9, 2024
Apache Zeppelin: Cron arbitrary user impersonation with improper privileges
Apr 9, 2024
Apache Zeppelin: Remote code execution by adding malicious JDBC connection string
Apr 9, 2024
Apache Zeppelin: Replacing other users notebook, bypassing any permissions
Apr 9, 2024
Apache Zeppelin: Denial of service with invalid notebook name
Apr 9, 2024
Apache Zeppelin: CSRF vulnerability in the Credentials page
Apr 9, 2024
Apache Zeppelin: Path traversal vulnerability
Apr 9, 2024
Apache Zeppelin: Stored XSS in note permissions
Dec 16, 2022
Apache Zeppelin: Arbitrary file deletion vulnerability
Dec 16, 2022
Cross Site Scripting in markdown interpreter
Sep 2, 2021
Notebook permissions bypass
Sep 2, 2021
bash command injection in spark interpreter
Sep 2, 2021
Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".
Apr 23, 2019
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as…
Apr 23, 2019
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user sess…
Apr 23, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-44615 | Path traversal in NotebookRepo note and folder path composition | MEDIUM | 0.80% | Jul 31, 2026 |
| CVE-2026-44617 | Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867 | MEDIUM | 0.84% | Jul 30, 2026 |
| CVE-2026-44616 | Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction | MEDIUM | 0.76% | Jul 30, 2026 |
| CVE-2026-44613 | Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling | MEDIUM | 0.39% | Jul 30, 2026 |
| CVE-2024-51775 | Apache Zeppelin: Command Injection via CSWSH | MEDIUM | 0.26% | Aug 3, 2025 |
| CVE-2024-41177 | Apache Zeppelin: XSS in the Helium module | MEDIUM | 0.64% | Aug 3, 2025 |
| CVE-2024-52279 | Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string | MEDIUM | 0.99% | Aug 3, 2025 |
| CVE-2024-41169 | Apache Zeppelin: raft directory listing and file read | HIGH | 0.65% | Jul 12, 2025 |
| CVE-2024-31867 | Apache Zeppelin: LDAP search filter query Injection Vulnerability | MEDIUM | 1.18% | Apr 9, 2024 |
| CVE-2024-31868 | Apache Zeppelin: XSS vulnerability in the helium module | MEDIUM | 1.31% | Apr 9, 2024 |
| CVE-2024-31866 | Apache Zeppelin: Interpreter download command does not escape malicious code injection | CRITICAL | 1.43% | Apr 9, 2024 |
| CVE-2024-31865 | Apache Zeppelin: Cron arbitrary user impersonation with improper privileges | MEDIUM | 1.72% | Apr 9, 2024 |
| CVE-2024-31864 | Apache Zeppelin: Remote code execution by adding malicious JDBC connection string | CRITICAL | 1.26% | Apr 9, 2024 |
| CVE-2024-31863 | Apache Zeppelin: Replacing other users notebook, bypassing any permissions | MEDIUM | 1.01% | Apr 9, 2024 |
| CVE-2024-31862 | Apache Zeppelin: Denial of service with invalid notebook name | MEDIUM | 1.36% | Apr 9, 2024 |
| CVE-2021-28656 | Apache Zeppelin: CSRF vulnerability in the Credentials page | MEDIUM | 0.48% | Apr 9, 2024 |
| CVE-2024-31860 | Apache Zeppelin: Path traversal vulnerability | MEDIUM | 1.39% | Apr 9, 2024 |
| CVE-2022-46870 | Apache Zeppelin: Stored XSS in note permissions | MEDIUM | 1.15% | Dec 16, 2022 |
| CVE-2021-28655 | Apache Zeppelin: Arbitrary file deletion vulnerability | MEDIUM | 1.58% | Dec 16, 2022 |
| CVE-2021-27578 | Cross Site Scripting in markdown interpreter | MEDIUM | 3.23% | Sep 2, 2021 |
| CVE-2020-13929 | Notebook permissions bypass | HIGH | 3.26% | Sep 2, 2021 |
| CVE-2019-10095 | bash command injection in spark interpreter | CRITICAL | 5.75% | Sep 2, 2021 |
| CVE-2018-1328 | Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph". | MEDIUM | 6.02% | Apr 23, 2019 |
| CVE-2018-1317 | In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication. | HIGH | 4.58% | Apr 23, 2019 |
| CVE-2017-12619 | Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone". | HIGH | 4.95% | Apr 23, 2019 |
Showing 1 to 25 of 25 CVEs