THREAT OPS › Threat News › CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
<p>Posted by Jongyoul Lee on Jul 30</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache Zeppelin 0.11.1 before 0.12.1<br /> <br /> Description:<br /> <br /> LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when <br /> constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter chara
Indicators of compromise
- CVE-2026-44617cve
- CVE-2024-31867cve
Original source: https://seclists.org/oss-sec/2026/q3/329