CVE-2022-46870: Apache Zeppelin: Stored XSS in note permissions
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. Users are recommended to upgrade to a supported version of Zeppelin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46870?
CVE-2022-46870 has a moderate severity level due to its risk of allowing logged-in users to execute arbitrary JavaScript in other users' browsers.
How do I fix CVE-2022-46870?
To fix CVE-2022-46870, upgrade Apache Zeppelin to version 0.8.2 or higher.
Who is affected by CVE-2022-46870?
CVE-2022-46870 affects users of Apache Zeppelin versions prior to 0.8.2.
What type of vulnerability is CVE-2022-46870?
CVE-2022-46870 is classified as a Cross-site Scripting (XSS) vulnerability.
Can CVE-2022-46870 be exploited remotely?
Yes, CVE-2022-46870 can be exploited remotely by logged-in users against other users.