CVE-2024-51775

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs.  This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.
References
Link Resource
https://github.com/apache/zeppelin/pull/4823 Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

History

05 Aug 2025, 16:15

Type Values Removed Values Added
CWE CWE-1385

05 Aug 2025, 15:59

Type Values Removed Values Added
CPE cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*
First Time Apache
Apache zeppelin
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://github.com/apache/zeppelin/pull/4823 - () https://github.com/apache/zeppelin/pull/4823 - Issue Tracking

03 Aug 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-03 11:15

Updated : 2025-08-05 16:15


NVD link : CVE-2024-51775

Mitre link : CVE-2024-51775


JSON object : View

Products Affected

apache

  • zeppelin
CWE

No CWE.