CVE-2018-1317

HIGH8.8EPSS 3.3%

Improper Authentication in Apache Zeppelin

Published: 4/24/2019Modified: 11/8/2023
Also known as:GHSA-9x2h-hvg6-4r5p

Description

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (4)