https://seclists.org/oss-sec/2024/q2/55: CVE-2024-31864: Apache Zeppelin: Remote code execution by adding malicious JDBC connection string
Published Apr 9, 2024
·Updated
Affected Software
1 affected component
Apache Zeppelin
Frequently Asked Questions
1
What is the severity of CVE-2024-31864?
CVE-2024-31864 has been classified as high severity due to its ability to allow remote code execution.
2
How do I fix CVE-2024-31864?
To fix CVE-2024-31864, upgrade to the latest version of Apache Zeppelin that addresses this vulnerability.
3
What systems are affected by CVE-2024-31864?
CVE-2024-31864 affects all versions of Apache Zeppelin prior to the patched release.
4
What is the impact of CVE-2024-31864?
The impact of CVE-2024-31864 includes potential unauthorized remote code execution on affected systems.
5
How can I confirm if my installation is vulnerable to CVE-2024-31864?
You can confirm vulnerability to CVE-2024-31864 by checking your Apache Zeppelin version against the patched versions listed in the security advisory.