CVE-2024-31863: Apache Zeppelin: Replacing other users notebook, bypassing any permissions
Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin. This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0.
Users are recommended to upgrade to version 0.11.0, which fixes the issue.
Other sources
Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0.
Users are recommended to upgrade to version 0.11.0, which fixes the issue.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31863?
CVE-2024-31863 has been classified as a high severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2024-31863?
To fix CVE-2024-31863, upgrade to Apache Zeppelin version 0.11.0 or later.
What versions of Apache Zeppelin are affected by CVE-2024-31863?
Apache Zeppelin versions from 0.10.1 before 0.11.0 are affected by CVE-2024-31863.
What type of vulnerability is CVE-2024-31863?
CVE-2024-31863 is an authentication bypass vulnerability resulting from spoofing.
Who should be concerned about CVE-2024-31863?
Organizations and individuals using affected versions of Apache Zeppelin should be concerned about CVE-2024-31863.