CVE-2021-28655

MEDIUM6.5EPSS 0.32%

Apache Zeppelin Improper Input Validation vulnerability

Published: 7/6/2023Modified: 2/16/2024

Description

The improper Input Validation vulnerability in `Move folder to Trash` feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

References (3)