CVE-2024-31865
Improper Input Validation vulnerability in Apache Zeppelin.
The attackers can call updating cron API with invalid or im
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
MEDIUM · CVSS 6.5
EPSS 0.00623
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0