CVE-2018-1328: XSS
Published Apr 23, 2019
·Updated
Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".
Affected Software
1 affected component
Apache Zeppelin<0.8.0
Event History
Apr 23, 2019
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1328?
CVE-2018-1328 is classified as a Medium severity vulnerability due to the potential for stored XSS attacks.
2
How do I fix CVE-2018-1328?
To fix CVE-2018-1328, upgrade Apache Zeppelin to version 0.8.0 or later.
3
What type of attack does CVE-2018-1328 enable?
CVE-2018-1328 enables stored Cross-Site Scripting (XSS) attacks through Note permissions.
4
Who reported the CVE-2018-1328 vulnerability?
The CVE-2018-1328 vulnerability was reported by Josna Joseph.
5
Which versions of Apache Zeppelin are affected by CVE-2018-1328?
Apache Zeppelin versions prior to 0.8.0 are affected by CVE-2018-1328.