CVE-2017-12619: Apache Zeppelin

High severity, CVSS 8.1. EPSS: 4.9% chance of exploitation in the next 30 days.

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".

Affected products

  • Apache Zeppelin: before 0.7.3 (fixed in 0.7.3)

Published 2019-04-23. Last modified 2026-06-17.