CVE-2024-31867: Apache Zeppelin: LDAP search filter query Injection Vulnerability
Published Apr 9, 2024
·Updated
Improper Input Validation vulnerability in Apache Zeppelin.
The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
Affected Software
2 affected componentsFixes available
maven/org.apache.zeppelin:zeppelin-server>=0.8.2<0.11.1
0.11.1
Apache Zeppelin>=0.8.2<0.11.1
Remediation
Patch Available
Event History
Apr 9, 2024
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
Severity
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-31867?
CVE-2024-31867 is categorized as a medium severity vulnerability due to improper input validation in Apache Zeppelin.
2
How do I fix CVE-2024-31867?
To fix CVE-2024-31867, upgrade Apache Zeppelin to version 0.11.1 or later.
3
What versions of Apache Zeppelin are affected by CVE-2024-31867?
CVE-2024-31867 affects Apache Zeppelin versions from 0.8.2 to before 0.11.1.
4
What type of vulnerability is CVE-2024-31867?
CVE-2024-31867 is an improper input validation vulnerability.
5
What can attackers do if CVE-2024-31867 is exploited?
If exploited, attackers can execute malicious queries by manipulating LDAP search filter configuration properties.