PT-2025-31783 · Apache · Apache Zeppelin

H Ming

·

Published

2025-08-03

·

Updated

2025-08-05

·

CVE-2024-52279

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Zeppelin versions 0.11.1 through 0.12.0
Description An improper input validation issue exists in Apache Zeppelin. The fix for JDBC URL validation did not account for URL encoded input.
Recommendations Upgrade to version 0.12.0.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-52279
GHSA-JR43-Q92Q-5Q82

Affected Products

Apache Zeppelin