VulnerabilityModified
CVE-2024-31860
Improper Input Validation vulnerability in Apache Zeppelin.
MEDIUM 6.5EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access. This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- apache/zeppelin
- Source
- security@apache.org
References
- https://github.com/apache/zeppelin/pull/4632Issue Tracking, Patch
- https://lists.apache.org/thread/c0zfjnow3oc3dzc8w5rbkzj8lqj5jm5xMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/04/09/2Mailing List
- https://github.com/apache/zeppelin/pull/4632Issue Tracking, Patch
- https://lists.apache.org/thread/c0zfjnow3oc3dzc8w5rbkzj8lqj5jm5xMailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.