VDB
CVE-2020-13929
CVE-2020-13929
PUBLISHED
CVSS 5 MEDIUM
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
EPSS 0.12% · 31.1th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
0.12%
31.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache Zeppelin | Apache Zeppelin |
| Maven | org.apache.zeppelin:zeppelin | 0 |
| apache | zeppelin | 0 |
Timeline
- Sep 2, 2021 CVE Published
- Sep 3, 2021 EPSS Score
- Sep 11, 2021 EPSS Score
- Oct 5, 2021 EPSS Score
- Oct 11, 2021 EPSS Score
- Oct 31, 2021 EPSS Score
- Nov 30, 2021 CVE Updated
- Dec 28, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 24, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 23, 2022 EPSS Score
References
- https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cusers.zeppelin.apache.org%3E url
- [oss-security] 20210902 CVE-2020-13929: Apache Zeppelin: Notebook permissions bypass mailing-list
- [announce] 20210902 CVE-2020-13929: Apache Zeppelin: Notebook permissions bypass mailing-list
- [zeppelin-users] 20210928 Re: CVE-2020-13929: Apache Zeppelin: Notebook permissions bypass mailing-list
- GLSA-202311-04 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-13929 advisory
- https://github.com/apache/zeppelin package
- https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028@%3Cannounce.apache.org%3E url
- https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028@%3Cusers.zeppelin.apache.org%3E url
- https://lists.apache.org/thread.html/r99529e175a7c1c9a26bd41a02802c8af7aa97319fe561874627eb999@%3Cusers.zeppelin.apache.org%3E url