PT-2025-31781 · Apache · Apache Zeppelin

H Ming

·

Published

2025-08-03

·

Updated

2025-08-03

·

CVE-2024-41177

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Zeppelin versions prior to 0.12.0
Description This issue is an incomplete blacklist leading to a Cross-Site Scripting (XSS) condition in Apache Zeppelin.
Recommendations Upgrade to version 0.12.0 to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-41177
GHSA-P288-459W-JXJ6

Affected Products

Apache Zeppelin