Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-17933
HistoryApr 11, 2024 - 12:00 a.m.

Apache Zeppelin Code Execution Vulnerability

2024-04-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
apache zeppelin
web-based
open source
laptop application
apache foundation
code execution vulnerability
shell scripts
malicious code
configurations
zeppelin_intp_classpath_overrides
data analysis
collaborative documentation
attacker
exploit

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

Apache Zeppelin is a Web-based open source laptop application from the Apache (USA) Foundation. The program supports interactive data analysis and collaborative documentation. Apache Zeppelin has a code execution vulnerability that can be exploited by an attacker to execute shell scripts or malicious code by overriding configurations like ZEPPELIN_INTP_CLASSPATH_OVERRIDES.

CPENameOperatorVersion
apache zeppelin >=0.8.2,lt0.11.1

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

Related for CNVD-2024-17933