CVE-2024-31861: Apache Zeppelin: Code injection by Shell interpreter

2024-04-10 Thread Jongyoul Lee
Severity: important Affected versions: - Apache Zeppelin 0.10.1 before 0.11.1 Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attackers can use Shell interpreter as a code generation gateway, and execute the generated code as a

CVE-2024-31867: Apache Zeppelin: LDAP search filter query Injection Vulnerability

2024-04-09 Thread Jongyoul Lee
Severity: moderate Affected versions: - Apache Zeppelin 0.8.2 before 0.11.1 Description: Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache

CVE-2024-31864: Apache Zeppelin: Remote code execution by adding malicious JDBC connection string

2024-04-09 Thread Jongyoul Lee
Severity: moderate Affected versions: - Apache Zeppelin before 0.11.1 Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver.

CVE-2024-31868: Apache Zeppelin: XSS vulnerability in the helium module

2024-04-09 Thread Jongyoul Lee
Severity: moderate Affected versions: - Apache Zeppelin 0.8.2 before 0.11.1 Description: Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2

CVE-2024-31866: Apache Zeppelin: Interpreter download command does not escape malicious code injection

2024-04-09 Thread Jongyoul Lee
Severity: moderate Affected versions: - Apache Zeppelin 0.8.2 before 0.11.1 Description: Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES.

CVE-2024-31865: Apache Zeppelin: Cron arbitrary user impersonation with improper privileges

2024-04-09 Thread Jongyoul Lee
Severity: moderate Affected versions: - Apache Zeppelin 0.8.2 before 0.11.1 Description: Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue

CVE-2024-31863: Apache Zeppelin: Replacing other users notebook, bypassing any permissions

2024-04-09 Thread Jongyoul Lee
Severity: moderate Affected versions: - Apache Zeppelin 0.10.1 before 0.11.0 Description: Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to

CVE-2024-31862: Apache Zeppelin: Denial of service with invalid notebook name

2024-04-09 Thread Jongyoul Lee
Severity: moderate Affected versions: - Apache Zeppelin 0.10.1 before 0.11.0 Description: Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to

CVE-2022-47894: Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXE

2024-04-09 Thread Jongyoul Lee
Severity: moderate Affected versions: - Apache Zeppelin SAP 0.8.0 before 0.11.0 Description: Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is retired, we do not plan to release a version that

CVE-2021-28656: Apache Zeppelin: CSRF vulnerability in the Credentials page

2024-04-09 Thread Jongyoul Lee
Severity: low Affected versions: - Apache Zeppelin through 0.9.0 Description: Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior

CVE-2024-31860: Apache Zeppelin: Path traversal vulnerability

2024-04-09 Thread Jongyoul Lee
Severity: low Affected versions: - Apache Zeppelin 0.9.0 before 0.11.0 Description: Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This

[ANNOUNCE] Apache Zeppelin 0.11.1 available

2024-04-02 Thread Jongyoul Lee
possible without you. Jongyoul Lee