CVE-2024-31863

Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:zeppelin:0.10.1:*:*:*:*:*:*:*

History

13 Feb 2025, 18:18

Type Values Removed Values Added
Summary (en) Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue. (en) Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

11 Feb 2025, 16:28

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:apache:zeppelin:0.10.1:*:*:*:*:*:*:*
References () http://www.openwall.com/lists/oss-security/2024/04/09/6 - () http://www.openwall.com/lists/oss-security/2024/04/09/6 - Mailing List
References () https://lists.apache.org/thread/3od2gfpwllmtc9c5ggw04ohn8s7w3ct9 - () https://lists.apache.org/thread/3od2gfpwllmtc9c5ggw04ohn8s7w3ct9 - Mailing List
First Time Apache zeppelin
Apache

21 Nov 2024, 09:14

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/04/09/6 - () http://www.openwall.com/lists/oss-security/2024/04/09/6 -
References () https://lists.apache.org/thread/3od2gfpwllmtc9c5ggw04ohn8s7w3ct9 - () https://lists.apache.org/thread/3od2gfpwllmtc9c5ggw04ohn8s7w3ct9 -
Summary
  • (es) Vulnerabilidad de omisión de autenticación mediante suplantación de identidad al reemplazar notas existentes en Apache Zeppelin. Este problema afecta a Apache Zeppelin: desde 0.10.1 antes de 0.11.0. Se recomienda a los usuarios actualizar a la versión 0.11.0, que soluciona el problema.

01 May 2024, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/04/09/6 -

09 Apr 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-09 11:15

Updated : 2025-03-25 19:15


NVD link : CVE-2024-31863

Mitre link : CVE-2024-31863

CVE.ORG link : CVE-2024-31863


JSON object : View

Products Affected

apache

  • zeppelin
CWE
CWE-290

Authentication Bypass by Spoofing