Medium severity6.5NVD Advisory· Published Apr 9, 2024· Updated Jun 17, 2026
CVE-2024-31860
CVE-2024-31860
Description
Improper Input Validation vulnerability in Apache Zeppelin.
By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access. This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0.
Users are recommended to upgrade to version 0.11.0, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.zeppelin:zeppelin-serverMaven | >= 0.9.0, < 0.11.0 | 0.11.0 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/apache/zeppelin/pull/4632nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-g64r-xf39-q4p5ghsaADVISORY
- lists.apache.org/thread/c0zfjnow3oc3dzc8w5rbkzj8lqj5jm5xnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-31860ghsaADVISORY
- www.openwall.com/lists/oss-security/2024/04/09/2nvdMailing ListWEB
- github.com/apache/zeppelin/commit/f025a697c1d1d0264064d5adf6cb0b20d85041b6ghsaWEB
News mentions
0No linked articles in our index yet.