CVE Published: 16/12/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Zeppelin Status : PUBLISHED
CVE-2022-46870 Description
An Improper Neutralization of Input During Web Page Generation (\'Cross-site Scripting\') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users\' browsers.
This issue affects Apache Zeppelin before 0.8.2. Users are recommended to upgrade to a supported version of Zeppelin.