Vulnerability Description
Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Zeppelin | < 0.12.0 |
Related Weaknesses (CWE)
References
- https://github.com/apache/zeppelin/pull/4755Issue Tracking
- https://github.com/apache/zeppelin/pull/4795ExploitIssue Tracking
- https://lists.apache.org/thread/nwh8vh9f3pnvt04n8z4g2kbddh62blr6Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/08/03/4
FAQ
What is CVE-2024-41177?
CVE-2024-41177 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the ...
How severe is CVE-2024-41177?
CVE-2024-41177 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41177?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Zeppelin.