GHSA-4qw8-pgpr-p9mq
GitHub Security Advisory
Bash command injection in Apache Zeppelin
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Affected Packages
Maven
org.apache.zeppelin:zeppelin
Affected versions:
0
(fixed in 0.10.0)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: November 26, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.