CVE-2020-13929: Apache Zeppelin

High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.

Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

Affected products

  • Apache Zeppelin: up to and including 0.9.0

Published 2021-09-02. Last modified 2026-06-17.