CVE-2024-51775

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs.  This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.
References
Link Resource
https://github.com/apache/zeppelin/pull/4823 Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

History

05 Aug 2025, 15:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*
References () https://github.com/apache/zeppelin/pull/4823 - () https://github.com/apache/zeppelin/pull/4823 - Issue Tracking
First Time Apache
Apache zeppelin

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de falta de validación de origen en WebSockets en Apache Zeppelin. El atacante podría acceder al servidor Zeppelin desde otro origen sin restricciones y obtener información interna sobre los párrafos. Este problema afecta a Apache Zeppelin desde la versión 0.11.1 hasta la 0.12.0. Se recomienda actualizar a la versión 0.12.0, que soluciona el problema.

03 Aug 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-03 11:15

Updated : 2025-08-05 16:15


NVD link : CVE-2024-51775

Mitre link : CVE-2024-51775

CVE.ORG link : CVE-2024-51775


JSON object : View

Products Affected

apache

  • zeppelin
CWE
CWE-1385

Missing Origin Validation in WebSockets