[MAVEN:GHSA-RRVF-5W4R-3X7V] Apache Zeppelin vulnerable to cross-site scripting in the helium module

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.

Attackers can modify helium.json and perform cross-site scripting attacks on normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.

Users are recommended to upgrade to version 0.11.1, which fixes the issue.

Package Affected Version
pkg:maven/org.apache.zeppelin/zeppelin-interpreter >= 0.8.2, < 0.11.1
ID
MAVEN:GHSA-RRVF-5W4R-3X7V
Severity
moderate
URL
https://github.com/advisories/GHSA-rrvf-5w4r-3x7v
Published
2024-04-09T18:30:22
(5 months ago)
Modified
2024-04-11T20:13:14
(5 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.zeppelin/zeppelin-interpreter org.apache.zeppelin zeppelin-interpreter >= 0.8.2 < 0.11.1
Fixed pkg:maven/org.apache.zeppelin/zeppelin-interpreter org.apache.zeppelin zeppelin-interpreter = 0.11.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...