CVE-2017-12619

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2019
Last modified:
07/11/2023

Description

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:* 0.7.3 (excluding)