VYPR

Maven package

org.apache.zeppelin/zeppelin-server

pkg:maven/org.apache.zeppelin/zeppelin-server

Vulnerabilities (6)

  • CVE-2024-41169Jul 12, 2025
    affected >= 0.10.1, < 0.12.0fixed 0.12.0

    The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes t

  • CVE-2024-31867Apr 9, 2024
    affected >= 0.8.2, < 0.11.1fixed 0.11.1

    Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version

  • CVE-2024-31865Apr 9, 2024
    affected >= 0.8.2, < 0.11.1fixed 0.11.1

    Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upg

  • CVE-2024-31863Apr 9, 2024
    affected >= 0.10.1, < 0.11.0fixed 0.11.0

    Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

  • CVE-2024-31862Apr 9, 2024
    affected >= 0.10.1, < 0.11.0fixed 0.11.0

    Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

  • CVE-2024-31860Apr 9, 2024
    affected >= 0.9.0, < 0.11.0fixed 0.11.0

    Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are re