Apache Zeppelin has a input validation errors vulnerablity

Published :
April 17, 2024
Vulnerability ID
CNVD-2024-17934
CVSS Score
7.8
Product Version
V1.0
Apache Zeppelin is an open-source web-based laptop application developed by the Apache Foundation in the United States. The program supports interactive data analysis and collaborative documentation. Apache Zeppelin has an input validation error vulnerability that allows an attacker to view the server account and access the contents of any file in the file system.

Affected Products

Product Name: Apache Zeppelin
Version: 0.9.0 <= Version < 0.11.0

Solution

The manufacturer has released a fix for the vulnerability, please update it in time:
https://lists.apache.org/thread/c0zfjnow3oc3dzc8w5rbkzj8lqj5jm5x

Kickstart Your Digitalization Journey by Harnessing the Power of AI to Optimize Operations

contact us