Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin.
The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver.
This issue affects Apache Zeppelin: before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
CVSS
No CVSS.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2024/04/09/8 | Mailing List |
http://www.openwall.com/lists/oss-security/2024/04/09/8 | Mailing List |
https://github.com/apache/zeppelin/pull/4709 | Issue Tracking |
https://github.com/apache/zeppelin/pull/4709 | Issue Tracking |
https://lists.apache.org/thread/752qdk0rnkd9nqtornz734zwb7xdwcdb | Mailing List Vendor Advisory |
https://lists.apache.org/thread/752qdk0rnkd9nqtornz734zwb7xdwcdb | Mailing List Vendor Advisory |
https://www.cve.org/CVERecord?id=CVE-2020-11974 | Not Applicable |
https://www.cve.org/CVERecord?id=CVE-2020-11974 | Not Applicable |
Configurations
History
05 May 2025, 20:27
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:* | |
References | () https://www.cve.org/CVERecord?id=CVE-2020-11974 - Not Applicable | |
References | () http://www.openwall.com/lists/oss-security/2024/04/09/8 - Mailing List | |
References | () https://lists.apache.org/thread/752qdk0rnkd9nqtornz734zwb7xdwcdb - Mailing List, Vendor Advisory | |
References | () https://github.com/apache/zeppelin/pull/4709 - Issue Tracking | |
First Time |
Apache
Apache zeppelin |
13 Feb 2025, 18:18
Type | Values Removed | Values Added |
---|---|---|
CWE | ||
Summary | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue. |
01 May 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
09 Apr 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-09 16:15
Updated : 2025-05-05 20:27
NVD link : CVE-2024-31864
Mitre link : CVE-2024-31864
JSON object : View
Products Affected
apache
- zeppelin
CWE
No CWE.