CVE-2026-44617

Published: Lug 30, 2026 Last Modified: Lug 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped.                   This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

90

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Read Application Data Modify Application Data
Applicable Platforms
Technologies: Database Server
View CWE Details
https://github.com/apache/zeppelin/pull/5226
https://lists.apache.org/thread/s65t6n3s1v4j5b1w7zvv5w73ko69m1zv
https://www.cve.org/CVERecord?id=CVE-2024-31867