PT-2024-24252 · Apache · Apache Zeppelin

·

CVE-2024-31864

·

Published

2024-04-09

·

Updated

2025-08-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Zeppelin versions prior to 0.11.1
Description The issue is related to improper control of code generation, allowing an attacker to inject sensitive configuration or malicious code when connecting to a MySQL database via a JDBC driver.
Recommendations For Apache Zeppelin versions prior to 0.11.1, upgrade to version 0.11.1 to fix the issue. As a temporary workaround, consider restricting access to the JDBC driver or disabling the code generation feature until the patch is applied.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31864
GHSA-66J8-C83M-GJ5F
GHSA-JR43-Q92Q-5Q82

Affected Products

Apache Zeppelin