logo

CVE-2024-31867 org.apache.zeppelin:zeppelin-server

Package

Manager: maven
Name: org.apache.zeppelin:zeppelin-server
Vulnerable Version: >=0.8.2 <0.11.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.01236 pctl0.78438

Details

Apache Zeppelin: LDAP search filter query Injection Vulnerability Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.

Metadata

Created: 2024-04-09T18:30:28Z
Modified: 2024-05-02T14:46:22Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-qmr3-52xf-wmhx/GHSA-qmr3-52xf-wmhx.json
CWE IDs: ["CWE-20", "CWE-90"]
Alternative ID: GHSA-qmr3-52xf-wmhx
Finding: F184
Auto approve: 1