Apache Zeppelin

Apache · 25 CVEs

CVE-2026-44615
MEDIUM

Path traversal in NotebookRepo note and folder path composition

Jul 31, 2026

CVE-2026-44617
MEDIUM

Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867

Jul 30, 2026

CVE-2026-44616
MEDIUM

Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction

Jul 30, 2026

CVE-2026-44613
MEDIUM

Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling

Jul 30, 2026

CVE-2024-51775
MEDIUM

Apache Zeppelin: Command Injection via CSWSH

Aug 3, 2025

CVE-2024-41177
MEDIUM

Apache Zeppelin: XSS in the Helium module

Aug 3, 2025

CVE-2024-52279
MEDIUM

Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string

Aug 3, 2025

CVE-2024-41169
HIGH

Apache Zeppelin: raft directory listing and file read

Jul 12, 2025

CVE-2024-31867
MEDIUM

Apache Zeppelin: LDAP search filter query Injection Vulnerability

Apr 9, 2024

CVE-2024-31868
MEDIUM

Apache Zeppelin: XSS vulnerability in the helium module

Apr 9, 2024

CVE-2024-31866
CRITICAL

Apache Zeppelin: Interpreter download command does not escape malicious code injection

Apr 9, 2024

CVE-2024-31865
MEDIUM

Apache Zeppelin: Cron arbitrary user impersonation with improper privileges

Apr 9, 2024

CVE-2024-31864
CRITICAL

Apache Zeppelin: Remote code execution by adding malicious JDBC connection string

Apr 9, 2024

CVE-2024-31863
MEDIUM

Apache Zeppelin: Replacing other users notebook, bypassing any permissions

Apr 9, 2024

CVE-2024-31862
MEDIUM

Apache Zeppelin: Denial of service with invalid notebook name

Apr 9, 2024

CVE-2021-28656
MEDIUM

Apache Zeppelin: CSRF vulnerability in the Credentials page

Apr 9, 2024

CVE-2024-31860
MEDIUM

Apache Zeppelin: Path traversal vulnerability

Apr 9, 2024

CVE-2022-46870
MEDIUM

Apache Zeppelin: Stored XSS in note permissions

Dec 16, 2022

CVE-2021-28655
MEDIUM

Apache Zeppelin: Arbitrary file deletion vulnerability

Dec 16, 2022

CVE-2021-27578
MEDIUM

Cross Site Scripting in markdown interpreter

Sep 2, 2021

CVE-2020-13929
HIGH

Notebook permissions bypass

Sep 2, 2021

CVE-2019-10095
CRITICAL

bash command injection in spark interpreter

Sep 2, 2021

CVE-2018-1328
MEDIUM

Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".

Apr 23, 2019

CVE-2018-1317
HIGH

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as…

Apr 23, 2019

CVE-2017-12619
HIGH

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user sess…

Apr 23, 2019

Showing 1 to 25 of 25 CVEs