CyberRota Analysis
AI-GeneratedApache Zeppelin versions 0.6.0 to 0.12.0 are vulnerable to a Cross-Site Request Forgery (CSRF) attack due to a permissive default CORS configuration that allows unauthorized cross-origin requests. This vulnerability can enable an attacker to execute actions on behalf of an authenticated user if they are tricked into visiting a malicious site. Organizations using affected versions should prioritize upgrading to version 0.12.1 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)