GHSA-9x2h-hvg6-4r5p
GitHub Security Advisory
Improper Authentication in Apache Zeppelin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.
Affected Packages
Maven
org.apache.zeppelin:zeppelin
Affected versions:
0
(fixed in 0.8.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: November 25, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.