# CVE-2024-41169

## Summary

- **CVE ID:** CVE-2024-41169
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-664
- **Published:** Jul 12, 2025
- **Last Modified:** Mar 13, 2026

## Description

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files.

This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0.

Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.

## Affected Products

- Apache Software Foundation — Apache Zeppelin (0.10.1)

## References

- [CNA](https://github.com/apache/zeppelin/pull/4841)
- [CNA](https://issues.apache.org/jira/browse/ZEPPELIN-6101)
- [CNA](https://lists.apache.org/thread/moyym04993c8owh4h0qj98r43tbo8qdd)
- [CVE](http://www.openwall.com/lists/oss-security/2025/07/13/1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.58%
- **EPSS Percentile:** 46.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._