Improper Input Validation vulnerability in Apache Zeppelin.

By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access. 
This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0.

Users are recommended to upgrade to version 0.11.0, which fixes the issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1201 Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.
Github GHSA Github GHSA GHSA-g64r-xf39-q4p5 Apache Zeppelin Path Traversal vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00309}

epss

{'score': 0.00403}


Tue, 06 May 2025 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Mon, 05 May 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CPEs cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

Thu, 13 Feb 2025 18:00:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue. Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-05-06T13:12:31.467Z

Reserved: 2024-04-06T11:49:32.612Z

Link: CVE-2024-31860

cve-icon Vulnrichment

Updated: 2024-08-02T01:59:49.933Z

cve-icon NVD

Status : Modified

Published: 2024-04-09T09:15:26.293

Modified: 2025-05-06T14:15:34.590

Link: CVE-2024-31860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.