← Back

CVE-2018-1317

nvd nist
Published: Apr 23, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.

Affected Products (1)

CPE details will appear after the next data sync.
1 product
Zeppelin

References (8)

Source: security@apache.org
Mailing ListRelease NotesThird Party Advisory
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.