Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-17934
HistoryApr 11, 2024 - 12:00 a.m.

Apache Zeppelin Input Validation Error Vulnerability (CNVD-2024-17934)

2024-04-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
apache zeppelin
web-based
open source
apache foundation
interactive data analysis
collaborative documentation
input validation error
attacker
server account
file system

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

Apache Zeppelin is a Web-based open source laptop application from the Apache (USA) Foundation. The program supports interactive data analysis and collaborative documentation. Apache Zeppelin suffers from an input validation error vulnerability that can be exploited by an attacker to view a server account and access the contents of any file on the file system.

CPENameOperatorVersion
apache zeppelin >=0.9.0,lt0.11.0

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

Related for CNVD-2024-17934