CVE-2017-12619

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-04-23 15:29

Updated : 2024-02-04 20:20


NVD link : CVE-2017-12619

Mitre link : CVE-2017-12619

CVE.ORG link : CVE-2017-12619


JSON object : View

Products Affected

apache

  • zeppelin
CWE
CWE-384

Session Fixation