CVE-2024-52279
- EPSS 0.33%
- Published 03.08.2025 10:15:27
- Last modified 05.08.2025 18:44:32
Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to ...
CVE-2024-41177
- EPSS 0.12%
- Published 03.08.2025 10:15:27
- Last modified 05.08.2025 16:35:15
Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.
CVE-2024-51775
- EPSS 0.05%
- Published 03.08.2025 10:13:17
- Last modified 05.08.2025 16:15:28
Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs. This issue affects Apache Zeppelin: ...
CVE-2024-41169
- EPSS 0.04%
- Published 12.07.2025 16:22:35
- Last modified 29.07.2025 15:07:15
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to...
CVE-2024-31867
- EPSS 1.24%
- Published 09.04.2024 17:16:03
- Last modified 05.05.2025 20:12:05
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are reco...
CVE-2024-31868
- EPSS 0.84%
- Published 09.04.2024 16:15:08
- Last modified 05.05.2025 20:11:35
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade ...
CVE-2024-31866
- EPSS 1.14%
- Published 09.04.2024 16:15:08
- Last modified 05.05.2025 20:09:58
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects Apache Zeppelin: from 0.8.2 be...
CVE-2024-31865
- EPSS 0.63%
- Published 09.04.2024 16:15:08
- Last modified 05.05.2025 20:27:58
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1....
CVE-2024-31864
- EPSS 1.16%
- Published 09.04.2024 16:15:08
- Last modified 05.05.2025 20:27:35
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before ...
CVE-2024-31863
- EPSS 0.14%
- Published 09.04.2024 11:15:31
- Last modified 25.03.2025 19:15:42
Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.