VYPR
High severity7.5NVD Advisory· Published Jul 12, 2025· Updated Jun 17, 2026

CVE-2024-41169

CVE-2024-41169

Description

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files.

This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0.

Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.zeppelin:zeppelin-interpreterMaven
>= 0.10.1, < 0.12.00.12.0
org.apache.zeppelin:zeppelin-serverMaven
>= 0.10.1, < 0.12.00.12.0

Affected products

4

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.