https://seclists.org/oss-sec/2024/q2/50: CVE-2021-28656: Apache Zeppelin: CSRF vulnerability in the Credentials page
Published Apr 9, 2024
·Updated
Affected Software
1 affected component
Apache Zeppelin
Frequently Asked Questions
1
What is the severity of CVE-2021-28656?
CVE-2021-28656 is classified as a medium severity vulnerability due to its potential for CSRF attacks affecting user credentials.
2
How do I fix CVE-2021-28656?
To fix CVE-2021-28656, upgrade to the latest version of Apache Zeppelin that has addressed this CSRF vulnerability.
3
What does CVE-2021-28656 affect?
CVE-2021-28656 affects the Credentials page in Apache Zeppelin, allowing attackers to exploit CSRF weaknesses.
4
Is CVE-2021-28656 present in all Apache Zeppelin versions?
CVE-2021-28656 affects multiple versions of Apache Zeppelin, specifically those prior to the patch release.
5
What should I do if I am vulnerable to CVE-2021-28656?
If you are vulnerable to CVE-2021-28656, you should immediately upgrade your installation of Apache Zeppelin to mitigate the risk.