First published: Tue Apr 09 2024(Updated: )
Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI. This issue affects Apache Zeppelin from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.zeppelin:zeppelin-server | >=0.10.1<0.11.0 | 0.11.0 |
Apache Zeppelin | >=0.10.1<0.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31862 is classified as a high severity vulnerability due to its improper input validation.
To fix CVE-2024-31862, upgrade Apache Zeppelin to version 0.11.0 or later.
CVE-2024-31862 affects Apache Zeppelin versions from 0.10.1 to just before 0.11.0.
CVE-2024-31862 is an improper input validation vulnerability occurring within the UI when creating new notes.
No known workaround exists for CVE-2024-31862; upgrading to the fixed version is the recommended approach.