PT-2024-24252 · Apache · Apache Zeppelin

Nbxiglk

+1

·

Published

2024-04-09

·

Updated

2025-08-05

·

CVE-2024-31864

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Zeppelin versions prior to 0.11.1
Description The issue is related to improper control of code generation, allowing an attacker to inject sensitive configuration or malicious code when connecting to a MySQL database via a JDBC driver.
Recommendations For Apache Zeppelin versions prior to 0.11.1, upgrade to version 0.11.1 to fix the issue. As a temporary workaround, consider restricting access to the JDBC driver or disabling the code generation feature until the patch is applied.

Fix

Code Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-31864
GHSA-66J8-C83M-GJ5F
GHSA-JR43-Q92Q-5Q82

Affected Products

Apache Zeppelin