Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2021-28655", "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09", "state": "PUBLISHED", "assignerShortName": "apache", "requesterUserId": "01d7ebfd-4418-401d-b8e4-f5ae3da29160", "dateReserved": "2021-03-17T08:27:06.184Z", "datePublished": "2022-12-16T12:51:51.927Z", "dateUpdated": "2024-08-03T21:47:33.056Z"}, "containers": {"cna": {"affected": [{"defaultStatus": "unaffected", "product": "Apache Zeppelin", "vendor": "Apache Software Foundation", "versions": [{"lessThanOrEqual": "0.9.0", "status": "affected", "version": "0", "versionType": "custom"}]}], "credits": [{"lang": "en", "type": "finder", "value": "Kai Zhao"}], "descriptions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "The improper Input Validation vulnerability in \"\u201dMove folder to Trash\u201d feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions."}], "value": "The improper Input Validation vulnerability in \"\u201dMove folder to Trash\u201d feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions."}], "metrics": [{"other": {"content": {"text": "important"}, "type": "Textual description of severity"}}], "problemTypes": [{"descriptions": [{"cweId": "CWE-20", "description": "CWE-20 Improper Input Validation", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09", "shortName": "apache", "dateUpdated": "2022-12-19T12:55:19.145Z"}, "references": [{"tags": ["vendor-advisory"], "url": "https://lists.apache.org/thread/bxs056g3xlsofz0jb3wny9dw4llwptd2"}], "source": {"discovery": "UNKNOWN"}, "title": "Apache Zeppelin: Arbitrary file deletion vulnerability", "x_generator": {"engine": "Vulnogram 0.1.0-dev"}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-03T21:47:33.056Z"}, "title": "CVE Program Container", "references": [{"tags": ["vendor-advisory", "x_transferred"], "url": "https://lists.apache.org/thread/bxs056g3xlsofz0jb3wny9dw4llwptd2"}]}]}}