First published: Fri Dec 16 2022(Updated: )
The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Zeppelin | <=0.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28655 is classified as a high severity vulnerability due to its potential to allow attackers to delete arbitrary files.
To fix CVE-2021-28655, upgrade Apache Zeppelin to version 0.9.1 or later, where the input validation issue has been addressed.
CVE-2021-28655 affects Apache Zeppelin versions 0.9.0 and earlier.
CVE-2021-28655 is an improper input validation vulnerability that can lead to file deletion by unauthorized users.
CVE-2021-28655 can be exploited by any attacker with access to the Apache Zeppelin application, enabling them to delete files.