CVE-2018-1328: Apache Zeppelin
Medium severity, CVSS 6.1. EPSS: 6% chance of exploitation in the next 30 days.
Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".
Affected products
- Apache Zeppelin: before 0.8.0 (fixed in 0.8.0)
Published 2019-04-23. Last modified 2026-06-17.