Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin.
The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs.
This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue.
References
Link | Resource |
---|---|
https://github.com/apache/zeppelin/pull/4823 | Issue Tracking |
Configurations
History
05 Aug 2025, 15:59
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CPE | cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:* | |
References | () https://github.com/apache/zeppelin/pull/4823 - Issue Tracking | |
First Time |
Apache
Apache zeppelin |
04 Aug 2025, 15:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 Aug 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-03 11:15
Updated : 2025-08-05 16:15
NVD link : CVE-2024-51775
Mitre link : CVE-2024-51775
CVE.ORG link : CVE-2024-51775
JSON object : View
Products Affected
apache
- zeppelin
CWE
CWE-1385
Missing Origin Validation in WebSockets