CVE-2024-41169
HIGHDescription
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.
Is your site exposed to CVE-2024-41169?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| apache | zeppelin |
References
Frequently Asked Questions
What is CVE-2024-41169? +
How severe is CVE-2024-41169? +
What products are affected by CVE-2024-41169? +
How do I check if I'm vulnerable to CVE-2024-41169? +
Related Vulnerabilities
OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is …
Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker …
Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a …
Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.