CVE-2017-12619

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

Information

Published : 2019-04-23 15:29

Updated : 2019-04-30 14:54


NVD link : CVE-2017-12619

Mitre link : CVE-2017-12619


JSON object : View

Products Affected

apache

  • zeppelin
CWE
CWE-384

Session Fixation