CVE-2021-28656

medium

Description

Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

References

https://lists.apache.org/thread/dttzkkv4qyn1rq2fdv1r94otb1osxztc

http://www.openwall.com/lists/oss-security/2024/04/09/3

Details

Source: Mitre, NVD

Published: 2024-04-09

Updated: 2025-05-05

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00053