VulnerabilityAnalyzed
CVE-2024-31867
Improper Input Validation vulnerability in Apache Zeppelin.
MEDIUM 6.5EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apache/zeppelin
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2024/04/09/12Mailing List
- https://github.com/apache/zeppelin/pull/4714Issue Tracking, Patch
- https://lists.apache.org/thread/s4scw8bxdhrjs0kg0lhb68xqd8y9lrtfMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/04/09/12Mailing List
- https://github.com/apache/zeppelin/pull/4714Issue Tracking, Patch
- https://lists.apache.org/thread/s4scw8bxdhrjs0kg0lhb68xqd8y9lrtfMailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.