https://seclists.org/oss-sec/2024/q2/53: CVE-2024-31863: Apache Zeppelin: Replacing other users notebook, bypassing any permissions
Published Apr 9, 2024
·Updated
Affected Software
1 affected component
Apache Zeppelin
Frequently Asked Questions
1
What is the severity of CVE-2024-31863?
CVE-2024-31863 is classified as a high severity vulnerability due to its potential to bypass user permissions.
2
How do I fix CVE-2024-31863?
To fix CVE-2024-31863, users should update to the latest version of Apache Zeppelin that addresses this vulnerability.
3
What type of vulnerability is CVE-2024-31863?
CVE-2024-31863 is a permission bypass vulnerability that allows unauthorized users to replace other users' notebooks.
4
Which software is affected by CVE-2024-31863?
Apache Zeppelin is the software affected by CVE-2024-31863.
5
When was CVE-2024-31863 published?
CVE-2024-31863 was published on April 9, 2024.