CVE-2024-41169: Apache Zeppelin
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.
Affected products
- Apache Zeppelin: from 0.10.1, before 0.12.0 (fixed in 0.12.0)
Published 2025-07-12. Last modified 2026-06-17.