LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped. This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
References
| Link | Resource |
|---|---|
| https://github.com/apache/zeppelin/pull/5226 | Issue Tracking Patch |
| https://lists.apache.org/thread/s65t6n3s1v4j5b1w7zvv5w73ko69m1zv | Mailing List Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2024-31867 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-30 16:17
Updated : 2026-08-05 17:22
NVD link : CVE-2026-44617
Mitre link : CVE-2026-44617
CVE.ORG link : CVE-2026-44617
JSON object : View
Products Affected
apache
- zeppelin
CWE
CWE-90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
