https://seclists.org/oss-sec/2024/q2/56: CVE-2024-31865: Apache Zeppelin: Cron arbitrary user impersonation with improper privileges
Published Apr 9, 2024
·Updated
Affected Software
1 affected component
Apache Zeppelin
Frequently Asked Questions
1
What is the severity of CVE-2024-31865?
CVE-2024-31865 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-31865?
To fix CVE-2024-31865, upgrade to the latest version of Apache Zeppelin that includes the security patch.
3
What does CVE-2024-31865 affect?
CVE-2024-31865 affects Apache Zeppelin, specifically related to cron arbitrary user impersonation due to improper privileges.
4
Can CVE-2024-31865 lead to a complete system compromise?
While CVE-2024-31865 allows for user impersonation, the impact largely depends on the privileges of the compromised user.
5
Is there a workaround for CVE-2024-31865 until I apply the patch?
There is no official workaround for CVE-2024-31865, so applying the patch is recommended for full protection.