Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.zeppelin:zeppelin(Maven) | 0 | 0.7.3 | N/A |
CVSS Metrics