CVE-2019-10095

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 10 (High)
100% Progress
EPSS 1.97 % (89th)
1.97% Progress
Affected Products 1
Advisories 2

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

Weaknesses
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2021-09-02 17:15:07
(3 years ago)
Updated Date
2023-11-24 14:15:07
(9 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Zeppelin 0.9.0 and prior versions cpe:2.3:a:apache:zeppelin <= 0.9.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...