CVE-2024-41169
published 2025-07-12CVE-2024-41169: The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.56%
43.4th percentile
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files.
This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | zeppelin | >= 0.10.1 < 0.12.0 | 0.12.0 |
| apache_software_foundation | apache_zeppelin | >= 0.10.1 < 0.12.0 | 0.12.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Zeppelin exposes server resources to unauthenticated attackers
ghsa·2025-07-12
CVE-2024-41169 [HIGH] CWE-664 Apache Zeppelin exposes server resources to unauthenticated attackers
Apache Zeppelin exposes server resources to unauthenticated attackers
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files.
This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.
OSV
Apache Zeppelin exposes server resources to unauthenticated attackers
osv·2025-07-12
CVE-2024-41169 [HIGH] Apache Zeppelin exposes server resources to unauthenticated attackers
Apache Zeppelin exposes server resources to unauthenticated attackers
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files.
This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-12
Published