Apache Zeppelin
cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*
- >= 0.10.1, < 0.12.0
An unauthenticated vulnerability in Apache Zeppelin versions 0.10.1 prior to 0.12.0 allows attackers to exploit the raft server protocol. This exploitation enables visibility into the server's resources, including directories and files. The vulnerability arises from the unauthorized access permitted by the raft protocol, leading to unauthorized resource enumeration.
Exploitation of this vulnerability allows for unauthorized directory and file access on the server.
Users are advised to upgrade to Apache Zeppelin version 0.12.0, which addresses this vulnerability by removing the Cluster Interpreter that utilizes the raft server protocol.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.