Apache Zeppelin up to 0.9.0 authentication spoofing [CVE-2020-13929]