In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.
{ "github_reviewed": true, "cwe_ids": [ "CWE-287" ], "severity": "HIGH", "github_reviewed_at": "2019-04-24T16:07:02Z", "nvd_published_at": "2019-04-23T15:29:00Z" }