CVE-2021-27578

Description

Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.937

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-27578 are fixed in Apache-zeppelin 0.9.0Windows
Vulnerabilities CVE-2021-27578 are fixed in Apache-zeppelin for Linux 0.9.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234