We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.
Reserved 2024-11-02 | Published 2025-08-03 | Updated 2025-08-03 | Assigner apacheCWE-1385 Missing Origin Validation in WebSockets
Calum Hutton
github.com/apache/zeppelin/pull/4823
Support options