CVE-2017-12619: High severity Apache Zeppelin vulnerability
Published Apr 23, 2019
·Updated
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
Affected Software
1 affected component
Apache Zeppelin<0.7.3
Event History
Apr 23, 2019
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-12619?
CVE-2017-12619 is classified as a medium severity vulnerability due to its potential to enable session hijacking.
2
How do I fix CVE-2017-12619?
To mitigate CVE-2017-12619, upgrade Apache Zeppelin to version 0.7.3 or later.
3
What systems are affected by CVE-2017-12619?
CVE-2017-12619 affects Apache Zeppelin versions before 0.7.3.
4
What type of vulnerability is CVE-2017-12619?
CVE-2017-12619 is a session fixation vulnerability.
5
Who reported CVE-2017-12619?
CVE-2017-12619 was reported by an individual known as 'stone lone'.