Medium severity6.5NVD Advisory· Published Apr 9, 2024· Updated Jun 17, 2026
CVE-2024-31865
CVE-2024-31865
Description
Improper Input Validation vulnerability in Apache Zeppelin.
The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges.
This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.zeppelin:zeppelin-serverMaven | >= 0.8.2, < 0.11.1 | 0.11.1 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/apache/zeppelin/pull/4631nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-g44m-x5h7-fr5qghsaADVISORY
- lists.apache.org/thread/slm1sf0slwc11f4m4r0nd6ot2rf7w81lnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-31865ghsaADVISORY
- www.openwall.com/lists/oss-security/2024/04/09/9nvdMailing ListWEB
- github.com/apache/zeppelin/commit/49e2740a1d83d58d2401ccf175fc91ffebfb0892ghsaWEB
News mentions
0No linked articles in our index yet.