This issue affects Apache Zeppelin: before 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54845 | Apache Zeppelin: XSS in the Helium module |
Github GHSA |
GHSA-p288-459w-jxj6 | Apache Zeppelin: XSS in the Helium module |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 05 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:* |
Mon, 04 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 04 Aug 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache zeppelin |
|
| Vendors & Products |
Apache
Apache zeppelin |
Sun, 03 Aug 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue. | |
| Title | Apache Zeppelin: XSS in the Helium module | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-04T21:08:43.404Z
Reserved: 2024-07-17T14:51:36.965Z
Link: CVE-2024-41177
Updated: 2025-11-04T21:08:43.404Z
Status : Modified
Published: 2025-08-03T10:15:27.240
Modified: 2025-11-04T22:16:02.777
Link: CVE-2024-41177
No data.
OpenCVE Enrichment
Updated: 2025-08-04T08:09:12Z
EUVD
Github GHSA