Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
History

Mon, 05 May 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache zeppelin
CPEs cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache zeppelin

Fri, 01 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-04-09T09:12:58.493Z

Updated: 2025-02-13T16:27:59.379Z

Reserved: 2021-03-17T08:27:58.338Z

Link: CVE-2021-28656

cve-icon Vulnrichment

Updated: 2024-08-03T21:47:32.969Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-09T10:15:07.610

Modified: 2025-05-05T20:49:50.420

Link: CVE-2021-28656

cve-icon Redhat

No data.