CVE-2024-52279

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

History

05 Aug 2025, 18:44

Type Values Removed Values Added
CPE cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.3
References () https://github.com/apache/zeppelin/pull/4838 - () https://github.com/apache/zeppelin/pull/4838 - Issue Tracking
References () https://issues.apache.org/jira/browse/ZEPPELIN-6095 - () https://issues.apache.org/jira/browse/ZEPPELIN-6095 - Issue Tracking
References () https://lists.apache.org/thread/dxb98vgrb21rrl3k0fzonpk66onr6o4q - () https://lists.apache.org/thread/dxb98vgrb21rrl3k0fzonpk66onr6o4q - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2024-31864 - () https://www.cve.org/CVERecord?id=CVE-2024-31864 - Not Applicable
First Time Apache
Apache zeppelin

05 Aug 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de validación de entrada incorrecta en Apache Zeppelin. La corrección para la validación de URL JDBC en CVE-2024-31864 no tenía en cuenta la entrada codificada por URL. Este problema afecta a Apache Zeppelin desde la versión 0.11.1 hasta la 0.12.0. Se recomienda a los usuarios actualizar a la versión 0.12.0, que soluciona el problema.

03 Aug 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-03 10:15

Updated : 2025-08-05 18:44


NVD link : CVE-2024-52279

Mitre link : CVE-2024-52279

CVE.ORG link : CVE-2024-52279


JSON object : View

Products Affected

apache

  • zeppelin
CWE
CWE-20

Improper Input Validation