The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files.
This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.
References
Configurations
No configuration.
History
15 Jul 2025, 13:14
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-12 17:15
Updated : 2025-07-15 13:14
NVD link : CVE-2024-41169
Mitre link : CVE-2024-41169
CVE.ORG link : CVE-2024-41169
JSON object : View
Products Affected
No product.
CWE
CWE-664
Improper Control of a Resource Through its Lifetime