CVE-2017-12619
CVE-2017-12619
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 4.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
23 Apr 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
Affected products
Apache Software Foundation · Apache ZeppelinWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →