Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-17938
HistoryApr 11, 2024 - 12:00 a.m.

Apache Zeppelin Code Injection Vulnerability (CNVD-2024-17938)

2024-04-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
apache zeppelin
code injection
vulnerability
apache foundation
web-based
open source
laptop application
attacker
sensitive configuration
malicious code
mysql database
jdbc driver

AI Score

9.5

Confidence

High

EPSS

0

Percentile

15.5%

Apache Zeppelin is a Web-based open source laptop application from the Apache (USA) Foundation. The program supports interactive data analysis and collaborative documentation. Apache Zeppelin suffers from a code injection vulnerability that stems from the application’s failure to properly filter special elements of constructed snippets, which can be exploited by an attacker to inject sensitive configuration or malicious code when connecting to a MySQL database via a JDBC driver.

AI Score

9.5

Confidence

High

EPSS

0

Percentile

15.5%