CVE-2021-28656: Apache Zeppelin: CSRF vulnerability in the Credentials page
Published Apr 9, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Affected Software
2 affected components
maven/org.apache.zeppelin:zeppelin-web<=0.9.0
Apache Zeppelin<=0.9.0
Event History
Apr 9, 2024
CVE Published
via MITRE·09:12 AM
Data Sourced
via MITRE·09:12 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
Severity
Advisory Published
via GitHub·12:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-28656?
CVE-2021-28656 is classified as a CVSS score of medium severity due to its potential for Cross-Site Request Forgery (CSRF) attacks.
2
How do I fix CVE-2021-28656?
To fix CVE-2021-28656, upgrade Apache Zeppelin to version 0.10.0 or later.
3
What type of vulnerability is CVE-2021-28656?
CVE-2021-28656 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which versions of Apache Zeppelin are affected by CVE-2021-28656?
CVE-2021-28656 affects Apache Zeppelin versions 0.9.0 and earlier.
5
What impact can CVE-2021-28656 have if exploited?
If exploited, CVE-2021-28656 allows an attacker to submit malicious requests which can compromise user credentials.