2025-02-13 19:04:13 +00:00

88 lines
3.0 KiB
JSON

{
"id": "CVE-2024-31864",
"sourceIdentifier": "security@apache.org",
"published": "2024-04-09T16:15:08.113",
"lastModified": "2025-02-13T18:18:00.517",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin.\n\nThe attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver.\nThis issue affects Apache Zeppelin: before 0.11.1.\n\nUsers are recommended to upgrade to version 0.11.1, which fixes the issue."
},
{
"lang": "es",
"value": "Vulnerabilidad de control inadecuado de generaci\u00f3n de c\u00f3digo (\"inyecci\u00f3n de c\u00f3digo\") en Apache Zeppelin. El atacante puede inyectar configuraci\u00f3n confidencial o c\u00f3digo malicioso al conectar la base de datos MySQL a trav\u00e9s del controlador JDBC. Este problema afecta a Apache Zeppelin: anteriores a 0.11.1. Se recomienda a los usuarios actualizar a la versi\u00f3n 0.11.1, que soluciona el problema."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "security@apache.org",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2024/04/09/8",
"source": "security@apache.org"
},
{
"url": "https://github.com/apache/zeppelin/pull/4709",
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread/752qdk0rnkd9nqtornz734zwb7xdwcdb",
"source": "security@apache.org"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2020-11974",
"source": "security@apache.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2024/04/09/8",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/apache/zeppelin/pull/4709",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.apache.org/thread/752qdk0rnkd9nqtornz734zwb7xdwcdb",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2020-11974",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}