Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0415 Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
Github GHSA Github GHSA GHSA-c538-924g-99q4 Session Fixation in Apache Zeppelin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-05T18:43:56.428Z

Reserved: 2017-08-07T00:00:00

Link: CVE-2017-12619

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-23T15:29:00.233

Modified: 2024-11-21T03:09:54.647

Link: CVE-2017-12619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses