Security Advisory

CVE-2017-12619

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-04-23 14:45:16
Last updated 2024-08-05 18:43:56
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".