CVE-2023-29216
- EPSS 4.81%
- Veröffentlicht 10.04.2023 08:15:07
- Zuletzt bearbeitet 13.02.2025 17:16:17
In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote co...
CVE-2023-29215
- EPSS 4.81%
- Veröffentlicht 10.04.2023 08:15:07
- Zuletzt bearbeitet 13.02.2025 17:16:17
In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code executi...
CVE-2023-27987
- EPSS 0.15%
- Veröffentlicht 10.04.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:52
In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrad...
CVE-2023-27603
- EPSS 0.39%
- Veröffentlicht 10.04.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:14
In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1...
CVE-2023-27602
- EPSS 0.56%
- Veröffentlicht 10.04.2023 08:15:06
- Zuletzt bearbeitet 13.02.2025 17:16:13
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2. For versions <=1.3.1, we suggest turning...
CVE-2022-44645
- EPSS 2.92%
- Veröffentlicht 31.01.2023 10:15:10
- Zuletzt bearbeitet 27.03.2025 15:15:38
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source an...
CVE-2022-44644
- EPSS 0.17%
- Veröffentlicht 31.01.2023 10:15:09
- Zuletzt bearbeitet 27.03.2025 15:15:37
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Ther...
CVE-2022-39944
- EPSS 2.42%
- Veröffentlicht 26.10.2022 16:15:11
- Zuletzt bearbeitet 07.05.2025 19:16:05
In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and mal...