CVE-2017-12619
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 4.9%
exploitation probability
4.9%top 8% of all CVEs
observed exploitation
nono source reports it
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
Affected products
Apache Software Foundation · Apache Zeppelin