CVE-2021-28656

CVE-2021-28656: Apache Zeppelin: CSRF vulnerability in the Credentials page

Vendor Apache Software Foundation
Product Apache Zeppelin
Weakness CWE-352 · CSRF
Published April 9, 2024
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

Key dates

Disclosure timeline

April 9, 2024 CVE published
February 13, 2025 Record updated