CVE-2024-31864
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
- Affected products
- Apache Zeppelin
- Apache Zeppelin
- < 0.11.1
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.3% (67th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2024-04-09
CVE-2024-31864 at NVD
No indexed exploits for CVE-2024-31864 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-31864 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.