Lucene search

K
cveApacheCVE-2021-28656
HistoryApr 09, 2024 - 10:15 a.m.

CVE-2021-28656

2024-04-0910:15:07
CWE-352
apache
web.nvd.nist.gov
26
csrf
apache zeppelin
credential page
vulnerability
nvd
cve-2021-28656
security

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%

Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

Affected configurations

Vulners
Node
apachezeppelinRange0.9.0
VendorProductVersionCPE
apachezeppelin*cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache Zeppelin",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "0.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%