First published: Tue Apr 09 2024(Updated: )
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. Attackers can modify `helium.json` and perform cross-site scripting attacks on normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.zeppelin:zeppelin-interpreter | >=0.8.2<0.11.1 | 0.11.1 |
Apache Zeppelin | >=0.8.2<0.11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31868 has been classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2024-31868, upgrade Apache Zeppelin to version 0.11.1 or later.
CVE-2024-31868 affects Apache Zeppelin versions from 0.8.2 up to, but not including, 0.11.1.
CVE-2024-31868 allows attackers to perform cross-site scripting (XSS) attacks on users by modifying helium.json.
Normal users of Apache Zeppelin versions from 0.8.2 to before 0.11.1 are at risk of being attacked via CVE-2024-31868.