Apache Zeppelin /api/configurations/all 未授权访问漏洞(CVE-2024-31861)

2026-04-30 Apache Zeppelin PoC No

Description

Apache Zeppelin 是一个让交互式数据分析变得可行的基于网页的开源框架。Zeppelin提供了数据分析、数据可视化等功能。在未设置网站账号密码的情况下,可以直接匿名访问到后台,攻击者可利用Zeppelin 中的shell功能执行任意命令。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities