VendorsApachezeppelinall versions
Vulnerabilities

Apache Software Foundation Zeppelin

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2019-10095
bash command injection in spark interpreter
Published 2021-09-02 · Modified
10.0EPSS 0.057
CVE-2024-31866
Apache Zeppelin: Interpreter download command does not escape malicious code injection
Published 2024-04-09 · Analyzed
9.8EPSS 0.014
CVE-2024-31864
Apache Zeppelin: Remote code execution by adding malicious JDBC connection string
Published 2024-04-09 · Modified
9.8EPSS 0.013
CVE-2018-1317
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.
Published 2019-04-23 · Modified
8.8EPSS 0.046
CVE-2017-12619
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
Published 2019-04-23 · Modified
8.1EPSS 0.049
CVE-2020-13929
Notebook permissions bypass
Published 2021-09-02 · Modified
7.5EPSS 0.033
CVE-2024-52279
Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string
Published 2025-08-03 · Modified
7.5EPSS 0.010
CVE-2024-41169
Apache Zeppelin: raft directory listing and file read
Published 2025-07-12 · Modified
7.5EPSS 0.006
CVE-2024-51775
Apache Zeppelin: Command Injection via CSWSH
Published 2025-08-03 · Modified
7.5EPSS 0.003
CVE-2024-31865
Apache Zeppelin: Cron arbitrary user impersonation with improper privileges
Published 2024-04-09 · Analyzed
6.5EPSS 0.017
CVE-2021-28655
Apache Zeppelin: Arbitrary file deletion vulnerability
Published 2022-12-16 · Modified
6.5EPSS 0.015
CVE-2024-31860
Apache Zeppelin: Path traversal vulnerability
Published 2024-04-09 · Modified
6.5EPSS 0.014
CVE-2024-31867
Apache Zeppelin: LDAP search filter query Injection Vulnerability
Published 2024-04-09 · Analyzed
6.5EPSS 0.012
CVE-2026-44615
Path traversal in NotebookRepo note and folder path composition
Published 2026-07-31 · Analyzed
6.5EPSS 0.006
CVE-2026-44617
Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
Published 2026-07-30 · Analyzed
6.5EPSS 0.005
CVE-2026-44616
Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Published 2026-07-30 · Analyzed
6.5EPSS 0.004
CVE-2018-1328
Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".
Published 2019-04-23 · Modified
6.1EPSS 0.060
CVE-2021-27578
Cross Site Scripting in markdown interpreter
Published 2021-09-02 · Modified
6.1EPSS 0.032
CVE-2024-31868
Apache Zeppelin: XSS vulnerability in the helium module
Published 2024-04-09 · Analyzed
6.1EPSS 0.013
CVE-2024-41177
Apache Zeppelin: XSS in the Helium module
Published 2025-08-03 · Modified
6.1EPSS 0.006
CVE-2026-44613
Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
Published 2026-07-30 · Modified
6.1EPSS 0.004
CVE-2022-46870
Apache Zeppelin: Stored XSS in note permissions
Published 2022-12-16 · Modified
5.4EPSS 0.011
CVE-2021-28656
Apache Zeppelin: CSRF vulnerability in the Credentials page
Published 2024-04-09 · Analyzed
5.4EPSS 0.005
CVE-2024-31862
Apache Zeppelin: Denial of service with invalid notebook name
Published 2024-04-09 · Analyzed
5.3EPSS 0.014
CVE-2022-47894
Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXE
Published 2024-04-09 · Analyzed
5.3EPSS 0.013
CVE-2024-31863
Apache Zeppelin: Replacing other users notebook, bypassing any permissions
Published 2024-04-09 · Modified
5.3EPSS 0.010