Re: CVE-2021-27578: Apache Zeppelin: Cross Site Scripting in markdown interpreter

2021-09-28 Thread Michiel Haisma
Hi Jeff, others, Can you please provide additional information regarding this vulnerability. Please include the following information: * Technical description of vulnerability, how users determine whether they are impacted. Maybe this is satisfied by one of the following items: * Relevant iss

CVE-2021-27578: Apache Zeppelin: Cross Site Scripting in markdown interpreter

2021-09-02 Thread Jeff Zhang
Description: Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0. Credit: Apache Zeppelin would like to thank Paulo Pacheco for reporting this i