Loading HuntDB...

GHSA-c538-924g-99q4

GitHub Security Advisory

Session Fixation in Apache Zeppelin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".

Affected Packages

Maven org.apache.zeppelin:zeppelin
Affected versions: 0 (fixed in 0.7.3)

Related CVEs

Key Information

GHSA ID
GHSA-c538-924g-99q4
Published
April 24, 2019 4:06 PM
Last Modified
August 3, 2021 6:51 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.zeppelin:zeppelin
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.