[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-31861Date: (C)2024-04-12   (M)2024-04-12


Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attackers can use Shell interpreter as a code generation gateway, and execute the generated code as a normal way. This issue affects Apache Zeppelin: from 0.10.1 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which doesn't have Shell interpreter by default.

Reference:
https://github.com/apache/zeppelin/pull/4708
https://lists.apache.org/thread/99clvqrht5l5r6kzjzwg2kj94boc9sfh

CWE    1
CWE-94
XCCDF    1

© SecPod Technologies