Maven package
org.apache.zeppelin/zeppelin-server
pkg:maven/org.apache.zeppelin/zeppelin-server
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-41169 | — | >= 0.10.1, < 0.12.0 | 0.12.0 | Jul 12, 2025 | The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes t | ||
| CVE-2024-31867 | — | >= 0.8.2, < 0.11.1 | 0.11.1 | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version | ||
| CVE-2024-31865 | — | >= 0.8.2, < 0.11.1 | 0.11.1 | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upg | ||
| CVE-2024-31863 | — | >= 0.10.1, < 0.11.0 | 0.11.0 | Apr 9, 2024 | Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue. | ||
| CVE-2024-31862 | — | >= 0.10.1, < 0.11.0 | 0.11.0 | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue. | ||
| CVE-2024-31860 | — | >= 0.9.0, < 0.11.0 | 0.11.0 | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access. This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are re |
- CVE-2024-41169Jul 12, 2025affected >= 0.10.1, < 0.12.0fixed 0.12.0
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes t
- CVE-2024-31867Apr 9, 2024affected >= 0.8.2, < 0.11.1fixed 0.11.1
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version
- CVE-2024-31865Apr 9, 2024affected >= 0.8.2, < 0.11.1fixed 0.11.1
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upg
- CVE-2024-31863Apr 9, 2024affected >= 0.10.1, < 0.11.0fixed 0.11.0
Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.
- CVE-2024-31862Apr 9, 2024affected >= 0.10.1, < 0.11.0fixed 0.11.0
Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.
- CVE-2024-31860Apr 9, 2024affected >= 0.9.0, < 0.11.0fixed 0.11.0
Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access. This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are re