CVE-2026-44617
Description
AI Translation Available
LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped. This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Read Application Data
Modify Application Data
Applicable Platforms
Technologies:
Database Server
https://github.com/apache/zeppelin/pull/5226
https://lists.apache.org/thread/s65t6n3s1v4j5b1w7zvv5w73ko69m1zv
https://www.cve.org/CVERecord?id=CVE-2024-31867