CVE-2024-31860: Apache Zeppelin: Path traversal vulnerability
Improper Input Validation vulnerability in Apache Zeppelin.
By adding relative path indicators (e.g ..), attackers can see the contents for any files in the filesystem that the server account can access. This issue affects Apache Zeppelin from 0.9.0 before 0.11.0.
Users are recommended to upgrade to version 0.11.0, which fixes the issue.
Other sources
Improper Input Validation vulnerability in Apache Zeppelin.
By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access. This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0.
Users are recommended to upgrade to version 0.11.0, which fixes the issue.
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31860?
CVE-2024-31860 has been classified as a high-severity vulnerability due to improper input validation allowing unauthorized file access.
How do I fix CVE-2024-31860?
To fix CVE-2024-31860, upgrade your Apache Zeppelin installation to version 0.11.0 or later.
What versions of Apache Zeppelin are affected by CVE-2024-31860?
CVE-2024-31860 affects Apache Zeppelin versions from 0.9.0 to below 0.11.0.
What type of vulnerability is CVE-2024-31860?
CVE-2024-31860 is an improper input validation vulnerability.
Can CVE-2024-31860 lead to data exposure?
Yes, CVE-2024-31860 can lead to data exposure by allowing attackers to access filesystem contents accessible to the server account.