6.5

CVE-2026-44617

Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped.                   This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Zeppelin Version >= 0.11.1 < 0.12.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.84% 0.543
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

https://github.com/apache/zeppelin/pull/5226
Patch
Issue Tracking
https://www.cve.org/CVERecord?id=CVE-2024-31867
Third Party Advisory
Mailing List
https://lists.apache.org/thread/s65t6n3s1v4j5b1w7zvv5w73ko69m1zv
Vendor Advisory
Mailing List