CVE-2024-51775

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs.  This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*

History

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/08/03/5 -

Information

Published : 2025-08-03 11:15

Updated : 2025-11-04 22:16


NVD link : CVE-2024-51775

Mitre link : CVE-2024-51775

CVE.ORG link : CVE-2024-51775


JSON object : View

Products Affected

apache

  • zeppelin
CWE
CWE-1385

Missing Origin Validation in WebSockets