Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.
History

Tue, 06 May 2025 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Mon, 05 May 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CPEs cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

Thu, 13 Feb 2025 18:00:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue. Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-04-09T09:08:28.802Z

Updated: 2025-05-06T13:12:31.467Z

Reserved: 2024-04-06T11:49:32.612Z

Link: CVE-2024-31860

cve-icon Vulnrichment

Updated: 2024-08-02T01:59:49.933Z

cve-icon NVD

Status : Modified

Published: 2024-04-09T09:15:26.293

Modified: 2025-05-06T14:15:34.590

Link: CVE-2024-31860

cve-icon Redhat

No data.