Apache Zeppelin: Interpreter download command does not escape malicious code injection
CVE-2024-31866
Currently unrated
Summary
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.
The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
Affected Version(s)
Apache Zeppelin 0.8.2 < 0.11.1
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Esa Hiltunen
https://teragrep.com