CVE-2024-31867 – org.apache.zeppelin:zeppelin-server
Package
Manager: maven
Name: org.apache.zeppelin:zeppelin-server
Vulnerable Version: >=0.8.2 <0.11.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.01236 pctl0.78438
Details
Apache Zeppelin: LDAP search filter query Injection Vulnerability Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
Metadata
Created: 2024-04-09T18:30:28Z
Modified: 2024-05-02T14:46:22Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-qmr3-52xf-wmhx/GHSA-qmr3-52xf-wmhx.json
CWE IDs: ["CWE-20", "CWE-90"]
Alternative ID: GHSA-qmr3-52xf-wmhx
Finding: F184
Auto approve: 1