CVE-2024-41177

CVE-2024-41177: Apache Zeppelin: XSS in the Helium module

Vendor Apache Software Foundation
Product Apache Zeppelin
Weakness CWE-79 · XSS
Published August 3, 2025
Last update November 4, 2025

CVSS base score

What the vulnerability does

Description

Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.

Key dates

Disclosure timeline

August 3, 2025 CVE published
November 4, 2025 Record updated