CVE-2024-41169
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.58%
- CWE
- CWE-664
- Published
- 2025-07-12
- Last modified
- 2026-03-13
Affected products
- Apache Software Foundation Apache Zeppelin
Weakness type
Related vulnerabilities
- CVE-2026-86203 — PocketMine-MP before 5.39.2 Item Duplication via Despawn State
- CVE-2026-20274 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-79289 — Improper control of a resource through its lifetime in Workers in Google Chrome prior to...
- CVE-2026-18549 — @fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit
- CVE-2026-19380 — Mullvad wireguard.sys IOCTL AdapterState reference count
- CVE-2026-20269 — Cisco IOS XE Software Security Hardening Release
- CVE-2026-20158 — Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities
- CVE-2025-34226 — OpenPLC Runtime v3 Persistent DoS