CVE-2024-31864
Apache Zeppelin: Remote code execution by adding malicious JDBC connection string
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver.
This issue affects Apache Zeppelin: before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
Vulnerabilidad de control inadecuado de generación de código ("inyección de código") en Apache Zeppelin. El atacante puede inyectar configuración confidencial o código malicioso al conectar la base de datos MySQL a través del controlador JDBC. Este problema afecta a Apache Zeppelin: anteriores a 0.11.1. Se recomienda a los usuarios actualizar a la versión 0.11.1, que soluciona el problema.
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-04-06 CVE Reserved
- 2024-04-09 CVE Published
- 2025-02-13 CVE Updated
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2024/04/09/8 |
|
|
https://www.cve.org/CVERecord?id=CVE-2020-11974 | Related |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/apache/zeppelin/pull/4709 | 2024-05-01 |
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/752qdk0rnkd9nqtornz734zwb7xdwcdb | 2024-05-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache Zeppelin Search vendor "Apache Software Foundation" for product "Apache Zeppelin" | < 0.11.1 Search vendor "Apache Software Foundation" for product "Apache Zeppelin" and version " < 0.11.1" | en |
Affected
|