📦 Zeppelin

by Apache

🔍 What is Zeppelin?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-31864

CRITICAL CVSS 9.8 Apr 9, 2024

This CVE-2024-31864 is a code injection vulnerability in Apache Zeppelin that allows attackers to execute arbitrary code when connecting to MySQL databases via JDBC drivers. It affects all Apache Zepp...

CVE-2024-31866

CRITICAL CVSS 9.8 Apr 9, 2024

This vulnerability in Apache Zeppelin allows attackers to execute arbitrary shell scripts or malicious code by manipulating configuration variables like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. It affects A...

CVE-2019-10095

CRITICAL CVSS 9.8 Sep 2, 2021

This CVE describes a command injection vulnerability in Apache Zeppelin's Spark interpreter settings that allows authenticated users to execute arbitrary system commands on the underlying server. The ...

CVE-2024-51775

MEDIUM CVSS 5.3 Aug 3, 2025

This CVE describes a missing origin validation vulnerability in Apache Zeppelin's WebSocket implementation. Attackers can bypass same-origin policy restrictions to access the Zeppelin server from unau...

CVE-2024-41177

MEDIUM CVSS 6.1 Aug 3, 2025

Apache Zeppelin versions before 0.12.0 have an incomplete blacklist that fails to properly sanitize user input, allowing attackers to inject malicious scripts. This Cross-Site Scripting (XSS) vulnerab...

CVE-2024-52279

MEDIUM CVSS 5.3 Aug 3, 2025

This vulnerability allows attackers to bypass JDBC URL validation in Apache Zeppelin by using URL-encoded input, potentially enabling unauthorized database connections or other injection attacks. It a...