CVE-2023-29215
- EPSS 3.11%
- Veröffentlicht 10.04.2023 08:15:07
- Zuletzt bearbeitet 13.02.2025 17:16:17
In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code executi...
CVE-2023-29216
- EPSS 3.11%
- Veröffentlicht 10.04.2023 08:15:07
- Zuletzt bearbeitet 13.02.2025 17:16:17
In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote co...
CVE-2023-27602
- EPSS 0.36%
- Veröffentlicht 10.04.2023 08:15:06
- Zuletzt bearbeitet 13.02.2025 17:16:13
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2. For versions <=1.3.1, we suggest turning...
CVE-2022-44645
- EPSS 2.66%
- Veröffentlicht 31.01.2023 10:15:10
- Zuletzt bearbeitet 27.03.2025 15:15:38
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source an...
CVE-2022-44644
- EPSS 0.11%
- Veröffentlicht 31.01.2023 10:15:09
- Zuletzt bearbeitet 27.03.2025 15:15:37
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Ther...
CVE-2022-39944
- EPSS 1.19%
- Veröffentlicht 26.10.2022 16:15:11
- Zuletzt bearbeitet 07.05.2025 19:16:05
In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and mal...