https://seclists.org/oss-sec/2024/q2/52: CVE-2024-31862: Apache Zeppelin: Denial of service with invalid notebook name
Published Apr 9, 2024
·Updated
Affected Software
1 affected component
Apache Zeppelin
Frequently Asked Questions
1
What is the severity of CVE-2024-31862?
CVE-2024-31862 has been classified as a medium severity vulnerability.
2
What causes CVE-2024-31862?
CVE-2024-31862 is caused by a denial of service vulnerability that occurs when an invalid notebook name is used in Apache Zeppelin.
3
How do I fix CVE-2024-31862?
To fix CVE-2024-31862, upgrade to the latest version of Apache Zeppelin that addresses the vulnerability.
4
Which versions of Apache Zeppelin are affected by CVE-2024-31862?
CVE-2024-31862 affects all versions of Apache Zeppelin prior to the patch that was released on April 9, 2024.
5
Can CVE-2024-31862 lead to data loss?
CVE-2024-31862 primarily leads to a denial of service and does not directly cause data loss.