{
  "from_raw": "Jongyoul Lee <jongyoul@apache.org>",
  "from": "Jongyoul Lee <jo...@apache.org>",
  "gravatar": "11bceeeb542d9d0cc305389f21d2c35f",
  "to": "an...@apache.org,\n de...@zeppelin.apache.org",
  "subject": "CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction",
  "message-id": "<0a83cdbd-3012-e8cb-4701-649876329f5f@apache.org>",
  "mid": "p6llqpvcszpg1wc8kx5ncfkdbms3g0rn",
  "permalinks": [
    "p6llqpvcszpg1wc8kx5ncfkdbms3g0rn",
    "r11d3ea6118d2ea9f96977bdf9b9e2a76253b48d95d603503efea9825@<announce.apache.org>"
  ],
  "dbid": "a5c8d68c3512742e41188726335270776e1ab2dd3941660d3dc37e41e0483e2a",
  "cc": "de...@zeppelin.apache.org",
  "epoch": 1785375531,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/07/30 01:38:51",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache Zeppelin 0.6.0 before 0.12.1\n\nDescription:\n\nLDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.\n\nCredit:\n\nAndrea Cosentino from Apache Software Foundation (finder)\n\nReferences:\n\nhttps://github.com/apache/zeppelin/pull/5226\nhttps://zeppelin.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-44616\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache Zeppelin 0.6.0 before 0.12.1\n\nDescription:\n\nLDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters ",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3365,
  "id": "p6llqpvcszpg1wc8kx5ncfkdbms3g0rn"
}