Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.
The attackers can modify helium.json and exposure XSS attacks to normal users.
This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
The attackers can modify helium.json and exposure XSS attacks to normal users.
This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 05 May 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache zeppelin |
|
CPEs | cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache zeppelin |
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 04 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 03 Oct 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-116 | |
References |
|
Thu, 03 Oct 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue. | Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue. |
Weaknesses | CWE-79 |

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-11-04T16:12:40.294Z
Reserved: 2024-04-06T11:51:21.885Z
Link: CVE-2024-31868

Updated: 2024-08-02T01:59:50.569Z

Status : Analyzed
Published: 2024-04-09T16:15:08.413
Modified: 2025-05-05T20:11:35.210
Link: CVE-2024-31868

No data.

No data.