PT-2025-29332 · Apache · Apache Zeppelin

Superx

·

Published

2025-07-12

·

Updated

2025-07-22

·

CVE-2024-41169

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Zeppelin versions 0.10.1 through 0.12.0
Description: An attacker can utilize the raft server protocol without authentication, enabling access to server resources, including directories and files.
Recommendations: Upgrade to version 0.12.0, which resolves the issue by removing the Cluster Interpreter.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-41169
GHSA-7PGF-PPXW-8624

Affected Products

Apache Zeppelin