CVE-2024-52279

CVE-2024-52279: Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string

Vendor Apache Software Foundation
Product Apache Zeppelin
Weakness CWE-20 · Input validation
Published August 3, 2025
Last update November 4, 2025

CVSS base score

What the vulnerability does

Description

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.

Key dates

Disclosure timeline

August 3, 2025 CVE published
November 4, 2025 Record updated