CVE-2021-28655: Apache Zeppelin: Arbitrary file deletion vulnerability
The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28655?
CVE-2021-28655 is classified as a high severity vulnerability due to its potential to allow attackers to delete arbitrary files.
How do I fix CVE-2021-28655?
To fix CVE-2021-28655, upgrade Apache Zeppelin to version 0.9.1 or later, where the input validation issue has been addressed.
What versions of Apache Zeppelin are affected by CVE-2021-28655?
CVE-2021-28655 affects Apache Zeppelin versions 0.9.0 and earlier.
What type of vulnerability is CVE-2021-28655?
CVE-2021-28655 is an improper input validation vulnerability that can lead to file deletion by unauthorized users.
Who can exploit CVE-2021-28655?
CVE-2021-28655 can be exploited by any attacker with access to the Apache Zeppelin application, enabling them to delete files.