CVE-2019-10095

CRITICAL9.8EPSS 3.0%

Bash command injection in Apache Zeppelin

Published: 9/7/2021Modified: 2/16/2024
Also known as:GHSA-4qw8-pgpr-p9mq

Description

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (10)