CVE-2018-1328: Apache Zeppelin

Medium severity, CVSS 6.1. EPSS: 6% chance of exploitation in the next 30 days.

Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".

Affected products

  • Apache Zeppelin: before 0.8.0 (fixed in 0.8.0)

Published 2019-04-23. Last modified 2026-06-17.