QID 731367
Date Published: 2024-04-11
QID 731367: Apache Zeppelin Path Traversal Vulnerability
Apache Zeppelin is a web-based notebook that enables data-driven, interactive data analytics and collaborative documents with SQL, Scala and more.
Apache Zeppelin applies insufficient input validation to relative paths. A remote attacker could exploit this vulnerability to access the contents of any files in the filesystem that the server account can access.
Affected versions:
Apache Zeppelin 0.9.0 before 0.11.0
QID Detection Logic:
This unauthenticated QID detects affected softwares based on the self reported version by Apache Zeppelin.
Successful exploitation allows a remote attacker to access the contents of any files in the filesystem that the server account can access.
Solution
Customers are advised to upgrade to Apache Zeppelin 0.11.0 or later versions to remediate this vulnerability.
Vendor References
- CVE-2024-31860 -
lists.apache.org/thread/c0zfjnow3oc3dzc8w5rbkzj8lqj5jm5x
CVEs related to QID 731367
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Zeppelin 0.11.0 or later |
|