- Description
- Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- zeppelin
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
- security@apache.org
- CWE-1385
- Hype score
- Not currently trending
Apache Zeppelin CVE-2024-52279: Arbitrary file read by adding malicious JDBC connection string https://t.co/romxOYxiUH CVE-2024-41177: XSS in the Helium module https://t.co/Setl0Kj9qA CVE-2024-51775: Command Injection via CSWSH https://t.co/dNuhE6KAtb
@oss_security
3 Aug 2025
547 Impressions
0 Retweets
6 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-51775 Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, … https://t.co/Hw0ON6K5QS
@CVEnew
3 Aug 2025
530 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B0F17B27-7AF8-4575-81FB-DD250ED7D8B1",
"versionEndExcluding": "0.12.0",
"versionStartIncluding": "0.11.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]