Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jiang Qingzhi

#49549of 56,337
5.4Total CVSS
Vulnerabilities · 1
PT-2024-10914
5.4
2024-04-09
Apache · Apache Zeppelin · CVE-2021-28656
**Name of the Vulnerable Software and Affected Versions** Apache Zeppelin versions 0.9.0 and prior versions **Description** A Cross-Site Request Forgery (CSRF) issue in the Credential page of Apache Zeppelin allows an attacker to submit malicious requests. **Recommendations** For Apache Zeppelin versions 0.9.0 and prior, consider disabling access to the Credential page until a fix is available. Restrict access to the Credential page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.