{"id":"GHSA-m65c-wmw9-vmpp","summary":"Apache Zeppelin: Replacing other users notebook, bypassing any permissions","details":"Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin. This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.","aliases":["CVE-2024-31863"],"modified":"2025-02-11T19:24:27.956655Z","published":"2024-04-09T12:30:47Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-09T18:53:31Z","nvd_published_at":"2024-04-09T11:15:31Z","cwe_ids":["CWE-290"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31863"},{"type":"WEB","url":"https://github.com/apache/zeppelin/commit/f025a697c1d1d0264064d5adf6cb0b20d85041b6"},{"type":"PACKAGE","url":"https://github.com/apache/zeppelin"},{"type":"WEB","url":"https://lists.apache.org/thread/3od2gfpwllmtc9c5ggw04ohn8s7w3ct9"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/04/09/6"}],"affected":[{"package":{"name":"org.apache.zeppelin:zeppelin-server","ecosystem":"Maven","purl":"pkg:maven/org.apache.zeppelin/zeppelin-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.10.1"},{"fixed":"0.11.0"}]}],"versions":["0.10.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-m65c-wmw9-vmpp/GHSA-m65c-wmw9-vmpp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}