Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin.
The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs. 
This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0.
Users are recommended to upgrade to version 0.12.0, which fixes the issue.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/apache/zeppelin/pull/4823 | Issue Tracking | 
Configurations
                    History
                    05 Aug 2025, 15:59
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:* | |
| First Time | 
        
        Apache zeppelin
         Apache  | 
|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 5.3  | 
| References | () https://github.com/apache/zeppelin/pull/4823 - Issue Tracking | 
04 Aug 2025, 15:06
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
03 Aug 2025, 11:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-08-03 11:15
Updated : 2025-08-05 16:15
NVD link : CVE-2024-51775
Mitre link : CVE-2024-51775
CVE.ORG link : CVE-2024-51775
JSON object : View
Products Affected
                apache
- zeppelin
 
CWE
                
                    
                        
                        CWE-1385
                        
            Missing Origin Validation in WebSockets
