CVE-2024-31862

MEDIUM5.3EPSS 0.21%

Apache Zeppelin: Denial of service with invalid notebook name

Published: 4/9/2024Modified: 2/13/2025
Also known as:GHSA-6623-c6mr-6737

Description

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI. This issue affects Apache Zeppelin from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References (6)