{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-02T15:09:43.087","vulnerabilities":[{"cve":{"id":"CVE-2024-31864","sourceIdentifier":"security@apache.org","published":"2024-04-09T16:15:08.113","lastModified":"2025-11-04T22:16:00.877","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin.\n\nThe attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver.\nThis issue affects Apache Zeppelin: before 0.11.1.\n\nUsers are recommended to upgrade to version 0.11.1, which fixes the issue."},{"lang":"es","value":"Vulnerabilidad de control inadecuado de generación de código (\"inyección de código\") en Apache Zeppelin. El atacante puede inyectar configuración confidencial o código malicioso al conectar la base de datos MySQL a través del controlador JDBC. Este problema afecta a Apache Zeppelin: anteriores a 0.11.1. Se recomienda a los usuarios actualizar a la versión 0.11.1, que soluciona el problema."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*","versionEndExcluding":"0.11.1","matchCriteriaId":"F2FE053F-B68F-4910-9388-9634FA1204F2"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2024/04/09/8","source":"security@apache.org","tags":["Mailing List"]},{"url":"https://github.com/apache/zeppelin/pull/4709","source":"security@apache.org","tags":["Issue Tracking"]},{"url":"https://lists.apache.org/thread/752qdk0rnkd9nqtornz734zwb7xdwcdb","source":"security@apache.org","tags":["Mailing List","Vendor Advisory"]},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-11974","source":"security@apache.org","tags":["Not Applicable"]},{"url":"http://www.openwall.com/lists/oss-security/2024/04/09/8","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"]},{"url":"http://www.openwall.com/lists/oss-security/2025/08/03/3","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/apache/zeppelin/pull/4709","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"]},{"url":"https://lists.apache.org/thread/752qdk0rnkd9nqtornz734zwb7xdwcdb","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"]},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-11974","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"]}]}}]}