{"id":"CVE-2024-31866","aliases":["GHSA-86jx-wr74-xr74"],"url":"https://o3.security/vulnerability/CVE-2024-31866","summary":"Apache Zeppelin: Interpreter download command does not escape malicious code injection","details":"Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.\n\nThe attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES.\nThis issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.\n\nUsers are recommended to upgrade to version 0.11.1, which fixes the issue.","published":"2024-04-09T16:09:12.117Z","modified":"2026-08-12T03:51:24.460523310Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.zeppelin:zeppelin-interpreter","fixedVersion":"0.11.1"}],"fix":{"url":"https://github.com/apache/zeppelin/pull/4715","label":"apache/zeppelin#4715"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/04/09/10"},{"type":"WEB","url":"https://repo.maven.apache.org/maven2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31866.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/jpkbq3oktopt34x2n5wnhzc2r1410ddd"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31866"},{"type":"FIX","url":"https://github.com/apache/zeppelin/pull/4715"},{"type":"WEB","url":"https://github.com/apache/zeppelin/commit/dd08a3966ef3b0b40f13d0291d7cac5ec3dd9f9c"},{"type":"PACKAGE","url":"https://github.com/apache/zeppelin"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.460523310Z"}}