Vulnerability Information CVE ID: CVE-2024-31864 Vulnerability Description: Apache Zeppelin: Remote Code Execution via Malicious JDBC Connection String Severity: Medium Affected Versions: - Apache Zeppelin versions prior to 0.11.1 Vulnerability Description: - Apache Zeppelin contains a vulnerability related to improper code generation control (code injection). - Attackers can inject sensitive configurations or malicious code when connecting to a MySQL database via JDBC driver. This issue affects Apache Zeppelin versions prior to 0.11.1. Mitigation Recommendation: - Users are advised to upgrade to version 0.11.1 to resolve the issue. Tracking ID: - ZEPPELIN-5990 Discoverer: - rg References: - https://github.com/apache/zeppelin/pull/4709 - https://www.cve.org/CVERecord?id=CVE-2020-11974 - https://zeppelin.apache.org/ - https://www.cve.org/CVERecord?id=CVE-2024-31864 - https://issues.apache.org/jira/browse/ZEPPELIN-5990