Lucene search

K
githubGitHub Advisory DatabaseGHSA-86JX-WR74-XR74
HistoryApr 09, 2024 - 6:30 p.m.

Improper escaping in Apache Zeppelin

2024-04-0918:30:22
CWE-116
GitHub Advisory Database
github.com
1
apache zeppelin
improper encoding
vulnerability
upgrade

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.

The attackers can execute shell scripts or malicious code by overriding configuration likeΒ ZEPPELIN_INTP_CLASSPATH_OVERRIDES.
This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.

Users are recommended to upgrade to version 0.11.1, which fixes the issue.

Affected configurations

Vulners
Node
org.apache.zeppelin\zeppelinMatchinterpreter

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

Related for GHSA-86JX-WR74-XR74