https://seclists.org/oss-sec/2024/q2/72: CVE-2024-31861: Apache Zeppelin: Code injection by Shell interpreter
Published Apr 10, 2024
·Updated
Affected Software
1 affected component
Apache Zeppelin
Frequently Asked Questions
1
What is the severity of CVE-2024-31861?
CVE-2024-31861 has been classified as a critical vulnerability due to its potential for code injection.
2
How do I fix CVE-2024-31861?
To fix CVE-2024-31861, upgrade to the patched version of Apache Zeppelin as provided in the official update.
3
What impact does CVE-2024-31861 have on Apache Zeppelin?
CVE-2024-31861 allows an attacker to execute arbitrary code on the server through the shell interpreter feature in Apache Zeppelin.
4
Who is affected by CVE-2024-31861?
All versions of Apache Zeppelin prior to the recent security update are affected by CVE-2024-31861.
5
Is there a workaround for CVE-2024-31861?
There is no known workaround for CVE-2024-31861 other than updating to a secure version of Apache Zeppelin.