{
  "from_raw": "Jongyoul Lee <jongyoul@apache.org>",
  "from": "Jongyoul Lee <jo...@apache.org>",
  "gravatar": "11bceeeb542d9d0cc305389f21d2c35f",
  "to": "an...@apache.org,\n de...@zeppelin.apache.org",
  "subject": "CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm \u2014 incomplete fix of CVE-2024-31867",
  "message-id": "<e4923efd-8bd4-585c-4e31-8bc7ab848659@apache.org>",
  "mid": "s65t6n3s1v4j5b1w7zvv5w73ko69m1zv",
  "permalinks": [
    "s65t6n3s1v4j5b1w7zvv5w73ko69m1zv",
    "3466960e75475bcb4ea0c48d32428d74b8fa9f5b32c68378766dfeac@<announce.apache.org>"
  ],
  "dbid": "f583570305c23204c773038a86493e9f94f3960426a11f0fc8a86da98d0a9116",
  "cc": "de...@zeppelin.apache.org",
  "epoch": 1785395602,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/07/30 07:13:22",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache Zeppelin 0.11.1 before 0.12.1\n\nDescription:\n\nLDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped. This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.\n\nCredit:\n\ndecsecre452 (finder)\n\nReferences:\n\nhttps://github.com/apache/zeppelin/pull/5226\nhttps://www.cve.org/CVERecord?id=CVE-2024-31867\nhttps://zeppelin.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-44617\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache Zeppelin 0.11.1 before 0.12.1\n\nDescription:\n\nLDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escapin",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3454,
  "id": "s65t6n3s1v4j5b1w7zvv5w73ko69m1zv"
}