CVE-2024-31860

CVE-2024-31860: Apache Zeppelin: Path traversal vulnerability

Vendor Apache Software Foundation
Product Apache Zeppelin
Weakness CWE-22 · Path traversal
Published April 9, 2024
Last update May 6, 2025

CVSS base score

What the vulnerability does

Description

Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

Key dates

Disclosure timeline

April 9, 2024 CVE published
May 6, 2025 Record updated