CVE-2024-31865: Apache Zeppelin: Cron arbitrary user impersonation with improper privileges
Improper Input Validation vulnerability in Apache Zeppelin.
The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges.
This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31865?
CVE-2024-31865 has been classified as a high-severity vulnerability due to improper input validation that allows unauthorized privilege escalation.
How do I fix CVE-2024-31865?
To mitigate CVE-2024-31865, users should upgrade to Apache Zeppelin version 0.11.1 or later.
Which versions of Apache Zeppelin are affected by CVE-2024-31865?
CVE-2024-31865 affects Apache Zeppelin versions from 0.8.2 to 0.11.0.
What type of vulnerability is CVE-2024-31865?
CVE-2024-31865 is classified as an improper input validation vulnerability.
What can attackers do with CVE-2024-31865?
Attackers can exploit CVE-2024-31865 to call the updating cron API with invalid privileges, allowing notebooks to run with elevated permissions.