Vulnerability record · CVE-2024-41169 · published 12 July 2025
CVE-2024-41169: Apache zeppelin vulnerability
Apache · Zeppelin
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.
Description
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/apache/zeppelin/pull/4841 | PatchVendor Advisory |
| https://issues.apache.org/jira/browse/ZEPPELIN-6101 | Issue TrackingPatch |
| https://lists.apache.org/thread/moyym04993c8owh4h0qj98r43tbo8qdd | Issue TrackingMailing ListPatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/07/13/1 |
Track CVE-2024-41169 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-41169), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.