CVE-2021-27578: Cross Site Scripting in markdown interpreter
Published Sep 2, 2021
·Updated
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0.
Affected Software
2 affected componentsFixes available
Apache Zeppelin<0.9.0
maven/org.apache.zeppelin:zeppelin<0.9.0
0.9.0
Event History
Sep 2, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Sep 7, 2021
Advisory Published
10:55 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-27578?
CVE-2021-27578 is classified as a moderate severity Cross Site Scripting vulnerability.
2
How do I fix CVE-2021-27578?
To fix CVE-2021-27578, upgrade your Apache Zeppelin installation to version 0.9.0 or later.
3
What versions of Apache Zeppelin are affected by CVE-2021-27578?
CVE-2021-27578 affects all Apache Zeppelin versions prior to 0.9.0.
4
What type of vulnerability is CVE-2021-27578?
CVE-2021-27578 is a Cross Site Scripting (XSS) vulnerability in the markdown interpreter of Apache Zeppelin.
5
Can an attacker exploit CVE-2021-27578 remotely?
Yes, an attacker can exploit CVE-2021-27578 remotely by injecting malicious scripts in the affected Apache Zeppelin versions.