CVE-2020-13929: Notebook permissions bypass
Published Sep 2, 2021
·Updated
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Affected Software
2 affected componentsFixes available
Apache Zeppelin<=0.9.0
maven/org.apache.zeppelin:zeppelin<0.10.0
0.10.0
Event History
Sep 2, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Sep 7, 2021
Advisory Published
10:56 PM
Frequently Asked Questions
1
What is CVE-2020-13929?
CVE-2020-13929 is an authentication bypass vulnerability in Apache Zeppelin that allows an attacker to bypass Zeppelin authentication mechanism to act as another user.
2
How does CVE-2020-13929 affect Apache Zeppelin?
CVE-2020-13929 affects Apache Zeppelin version 0.9.0 and prior versions.
3
What is the severity of CVE-2020-13929?
CVE-2020-13929 has a severity rating of 7.5 (High).
4
How can an attacker exploit CVE-2020-13929?
An attacker can exploit CVE-2020-13929 by bypassing the Zeppelin authentication mechanism to act as another user.
5
Is there a fix available for CVE-2020-13929?
Yes, upgrading to a version of Apache Zeppelin that is not affected by CVE-2020-13929 will fix the vulnerability.