First published: Tue Apr 09 2024(Updated: )
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.zeppelin:zeppelin-jdbc | <0.11.1 | 0.11.1 |
Apache Zeppelin | <0.11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31864 is considered a high-severity vulnerability due to its potential for code injection.
To mitigate CVE-2024-31864, upgrade Apache Zeppelin to version 0.11.1 or later.
CVE-2024-31864 affects Apache Zeppelin versions prior to 0.11.1 when connecting to MySQL databases via the JDBC driver.
CVE-2024-31864 is classified as an Improper Control of Generation of Code ('Code Injection') vulnerability.
Attackers exploiting CVE-2024-31864 can inject sensitive configurations or malicious code via JDBC connections.