Apache / Zeppelin
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44615 | Path traversal in NotebookRepo note and folder path composition | MEDIUM | 6.5 | Jul 31, 2026 |
| CVE-2026-44617 | Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867 | MEDIUM | 6.5 | Jul 30, 2026 |
| CVE-2026-44616 | Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction | MEDIUM | 6.5 | Jul 30, 2026 |
| CVE-2026-44613 | Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling | MEDIUM | 6.1 | Jul 30, 2026 |
| CVE-2024-51775 | Apache Zeppelin: Command Injection via CSWSH | MEDIUM | 6.9 | Aug 3, 2025 |
| CVE-2024-41177 | Apache Zeppelin: XSS in the Helium module | MEDIUM | 6.1 | Aug 3, 2025 |
| CVE-2024-52279 | Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string | MEDIUM | 6.6 | Aug 3, 2025 |
| CVE-2024-41169 | Apache Zeppelin: raft directory listing and file read | HIGH | 7.5 | Jul 12, 2025 |
| CVE-2024-31867 | Apache Zeppelin: LDAP search filter query Injection Vulnerability | MEDIUM | 6.5 | Apr 9, 2024 |
| CVE-2024-31868 | Apache Zeppelin: XSS vulnerability in the helium module | MEDIUM | 5.3 | Apr 9, 2024 |
| CVE-2024-31866 | Apache Zeppelin: Interpreter download command does not escape malicious code injection | CRITICAL | 9.3 | Apr 9, 2024 |
| CVE-2024-31865 | Apache Zeppelin: Cron arbitrary user impersonation with improper privileges | MEDIUM | 6.5 | Apr 9, 2024 |
| CVE-2024-31864 | Apache Zeppelin: Remote code execution by adding malicious JDBC connection string | CRITICAL | 9.8 | Apr 9, 2024 |
| CVE-2024-31863 | Apache Zeppelin: Replacing other users notebook, bypassing any permissions | MEDIUM | 6.5 | Apr 9, 2024 |
| CVE-2024-31862 | Apache Zeppelin: Denial of service with invalid notebook name | MEDIUM | 5.3 | Apr 9, 2024 |
| CVE-2022-47894 | Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXE | MEDIUM | 5.3 | Apr 9, 2024 |
| CVE-2021-28656 | Apache Zeppelin: CSRF vulnerability in the Credentials page | MEDIUM | 5.4 | Apr 9, 2024 |
| CVE-2024-31860 | Apache Zeppelin: Path traversal vulnerability | MEDIUM | 6.5 | Apr 9, 2024 |
| CVE-2022-46870 | Apache Zeppelin: Stored XSS in note permissions | MEDIUM | 5.4 | Dec 16, 2022 |
| CVE-2021-28655 | Apache Zeppelin: Arbitrary file deletion vulnerability | MEDIUM | 6.5 | Dec 16, 2022 |
| CVE-2021-27578 | Cross Site Scripting in markdown interpreter | MEDIUM | 6.1 | Sep 2, 2021 |
| CVE-2020-13929 | Notebook permissions bypass | HIGH | 7.5 | Sep 2, 2021 |
| CVE-2019-10095 | bash command injection in spark interpreter | CRITICAL | 9.8 | Sep 2, 2021 |
| CVE-2018-1328 | Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph". | MEDIUM | 6.1 | Apr 23, 2019 |
| CVE-2018-1317 | In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication. | HIGH | 8.8 | Apr 23, 2019 |
Showing 1 to 25 of 26 CVEs