The attackers can modify helium.json and exposure XSS attacks to normal users.
This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.
Users are recommended to upgrade to version 0.11.1, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rrvf-5w4r-3x7v | Apache Zeppelin vulnerable to cross-site scripting in the helium module |
Mon, 05 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache zeppelin |
|
| CPEs | cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache zeppelin |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 04 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 03 Oct 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 | |
| References |
|
Thu, 03 Oct 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue. | Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue. |
| Weaknesses | CWE-79 |
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-11-04T16:12:40.294Z
Reserved: 2024-04-06T11:51:21.885Z
Link: CVE-2024-31868
Updated: 2024-08-02T01:59:50.569Z
Status : Analyzed
Published: 2024-04-09T16:15:08.413
Modified: 2025-05-05T20:11:35.210
Link: CVE-2024-31868
No data.
OpenCVE Enrichment
No data.
Github GHSA