PT-2024-24256 · Apache · Apache Zeppelin

H Ming

·

Published

2024-04-09

·

Updated

2025-05-05

·

CVE-2024-31868

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Zeppelin versions 0.8.2 through 0.11.0
Description The issue is related to improper encoding or escaping of output, allowing attackers to modify helium.json and perform cross-site scripting attacks on normal users.
Recommendations For Apache Zeppelin versions 0.8.2 through 0.11.0, upgrade to version 0.11.1, which fixes the issue. As a temporary workaround, consider restricting access to the helium.json file to minimize the risk of exploitation.

Fix

Improper Encoding or Escaping of Output

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-31868
GHSA-RRVF-5W4R-3X7V

Affected Products

Apache Zeppelin