Apache

Zeppelin

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.84%
  • Veröffentlicht 31.07.2026 11:17:10
  • Zuletzt bearbeitet 10.08.2026 14:20:00

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths.          ...

  • EPSS 0.84%
  • Veröffentlicht 30.07.2026 15:22:39
  • Zuletzt bearbeitet 05.08.2026 17:22:36

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped.          ...

  • EPSS 0.45%
  • Veröffentlicht 30.07.2026 15:21:21
  • Zuletzt bearbeitet 05.08.2026 17:23:15

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint       ...

  • EPSS 0.39%
  • Veröffentlicht 30.07.2026 15:19:40
  • Zuletzt bearbeitet 07.08.2026 14:16:59

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a         ...

  • EPSS 0.92%
  • Veröffentlicht 03.08.2025 10:15:27
  • Zuletzt bearbeitet 04.11.2025 22:16:04

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to ...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 03.08.2025 10:15:27
  • Zuletzt bearbeitet 04.11.2025 22:16:02

Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.

  • EPSS 0.25%
  • Veröffentlicht 03.08.2025 10:13:17
  • Zuletzt bearbeitet 04.11.2025 22:16:04

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs.  This issue affects Apache Zeppelin: ...

  • EPSS 0.56%
  • Veröffentlicht 12.07.2025 16:22:35
  • Zuletzt bearbeitet 04.11.2025 22:16:02

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to...

  • EPSS 1.78%
  • Veröffentlicht 09.04.2024 17:16:03
  • Zuletzt bearbeitet 05.05.2025 20:12:05

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are reco...

  • EPSS 1.26%
  • Veröffentlicht 09.04.2024 16:15:08
  • Zuletzt bearbeitet 04.11.2025 22:16:00

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before ...