Lucene search

K
cve[email protected]CVE-2024-31864
HistoryApr 09, 2024 - 4:15 p.m.

CVE-2024-31864

2024-04-0916:15:08
CWE-94
web.nvd.nist.gov
28
cve-2024-31864
improper control of generation of code
code injection
apache zeppelin
mysql database
jdbc driver
security vulnerability
upgrade

9.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%

Improper Control of Generation of Code (‘Code Injection’) vulnerability in Apache Zeppelin.

The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver.
This issue affects Apache Zeppelin: before 0.11.1.

Users are recommended to upgrade to version 0.11.1, which fixes the issue.

Affected configurations

Vulners
Node
apachezeppelinRange0.11.1

CNA Affected

[
  {
    "collectionURL": "https://repo.maven.apache.org/maven2",
    "defaultStatus": "unaffected",
    "product": "Apache Zeppelin",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "0.11.1",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

9.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%

Related for CVE-2024-31864