Vulnerability Description
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Zeppelin | < 0.9.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2021/09/02/3Mailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r31012f2c8e39a5e12e14c1de030012cb8b51c037d9
- https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b0
- https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b0Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b0Mailing ListVendor Advisory
- https://security.gentoo.org/glsa/202311-04
- http://www.openwall.com/lists/oss-security/2021/09/02/3Mailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r31012f2c8e39a5e12e14c1de030012cb8b51c037d9
- https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b0
- https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b0Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b0Mailing ListVendor Advisory
- https://security.gentoo.org/glsa/202311-04
FAQ
What is CVE-2021-27578?
CVE-2021-27578 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0...
How severe is CVE-2021-27578?
CVE-2021-27578 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27578?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Zeppelin.