CVE-2019-10095: bash command injection in spark interpreter
Published Sep 2, 2021
·Updated
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Affected Software
2 affected componentsFixes available
Apache Zeppelin<=0.9.0
maven/org.apache.zeppelin:zeppelin<0.10.0
0.10.0
Event History
Sep 2, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Sep 7, 2021
Advisory Published
10:56 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-10095?
CVE-2019-10095 has a medium severity rating due to its potential for command injection.
2
How do I fix CVE-2019-10095?
To fix CVE-2019-10095, upgrade to Apache Zeppelin version 0.10.0 or later.
3
What versions of Apache Zeppelin are affected by CVE-2019-10095?
CVE-2019-10095 affects Apache Zeppelin versions 0.9.0 and earlier.
4
What type of vulnerability is CVE-2019-10095?
CVE-2019-10095 is a bash command injection vulnerability.
5
Which components are impacted by CVE-2019-10095?
The Spark interpreter settings in Apache Zeppelin are impacted by CVE-2019-10095.