Логотип exploitDog
bind:CVE-2024-31865
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-31865

Количество 2

Количество 2

nvd логотип

CVE-2024-31865

почти 2 года назад

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-g44m-x5h7-fr5q

почти 2 года назад

Apache Zeppelin: Cron arbitrary user impersonation with improper privileges

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-31865

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-g44m-x5h7-fr5q

Apache Zeppelin: Cron arbitrary user impersonation with improper privileges

CVSS3: 5.4
1%
Низкий
почти 2 года назад

Уязвимостей на страницу