Loading HuntDB...

GHSA-9x2h-hvg6-4r5p

GitHub Security Advisory

Improper Authentication in Apache Zeppelin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.

Affected Packages

Maven org.apache.zeppelin:zeppelin
Affected versions: 0 (fixed in 0.8.0)

Related CVEs

Key Information

GHSA ID
GHSA-9x2h-hvg6-4r5p
Published
April 24, 2019 4:06 PM
Last Modified
August 3, 2021 7:00 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.zeppelin:zeppelin
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.