Descripción
Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user-s behalf through REST and WebSocket endpoints. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
CVSS 6.1EPSS 0.387%Riesgo 0.63
Ver fuente- Publicación
- 2026-07-30 16:17:12
- Versiones afectadas
- >=0.6.0,<0.12.1
- Tipo
- Aplicación web
- Última modificación
- 2026-08-07 14:16:59
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N