Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
History

Mon, 05 May 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache zeppelin
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache zeppelin

Thu, 13 Feb 2025 18:00:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue. Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.

Fri, 06 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-04-09T16:15:47.978Z

Updated: 2025-02-13T17:52:00.183Z

Reserved: 2024-04-06T11:51:11.435Z

Link: CVE-2024-31867

cve-icon Vulnrichment

Updated: 2024-08-02T01:59:49.387Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-09T17:16:03.237

Modified: 2025-05-05T20:12:05.860

Link: CVE-2024-31867

cve-icon Redhat

No data.