Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-31864


Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.


Published

2024-04-09T16:15:08.113

Last Modified

2025-11-04T22:16:00.877

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache zeppelin < 0.11.1 Yes

References