Severity
9.8CRITICAL
EPSS
0.8%
top 25.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateAug 3

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDapache/zeppelin< 0.11.1
CVEListV5apache_software_foundation/apache_zeppelin0.11.10.12.0+1

🔴Vulnerability Details

4
GHSA
Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string2025-08-03
OSV
Apache Zeppelin remote code execution by adding malicious JDBC connection string2024-04-09
GHSA
Apache Zeppelin remote code execution by adding malicious JDBC connection string2024-04-09
CVEList
Apache Zeppelin: Remote code execution by adding malicious JDBC connection string2024-04-09
CVE-2024-31864 (CRITICAL CVSS 9.8) | Improper Control of Generation of C | cvebase.io