Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
History

Mon, 05 May 2025 20:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

Thu, 13 Feb 2025 18:00:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue. Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-04-09T16:07:36.358Z

Updated: 2025-02-13T17:48:06.867Z

Reserved: 2024-04-06T11:50:47.384Z

Link: CVE-2024-31865

cve-icon Vulnrichment

Updated: 2024-04-22T18:48:29.121Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-09T16:15:08.213

Modified: 2025-05-05T20:27:58.593

Link: CVE-2024-31865

cve-icon Redhat

No data.