{"id":"CVE-2024-31861","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-31861","summary":"Code injection in Apache Zeppelin Shell","details":"Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin.\n\nThe attackers can use Shell interpreter as a code generation gateway, and execute the generated code as a normal way.\nThis issue affects Apache Zeppelin: from 0.10.1 before 0.11.1.\n\nUsers are recommended to upgrade to version 0.11.1, which doesn't have Shell interpreter by default.\n\n","published":"2024-04-11T09:30:56Z","modified":"2024-12-03T06:09:21.028891Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.zeppelin:zeppelin-shell","fixedVersion":"0.11.1"}],"fix":{"url":"https://github.com/apache/zeppelin/pull/4708","label":"apache/zeppelin#4708"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31861"},{"type":"WEB","url":"https://github.com/apache/zeppelin/pull/4708"},{"type":"PACKAGE","url":"https://github.com/apache/zeppelin"},{"type":"WEB","url":"https://lists.apache.org/thread/99clvqrht5l5r6kzjzwg2kj94boc9sfh"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/04/10/8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-03T06:09:21.028891Z"}}