Apache

Linkis

16 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.11%
  • Published 10.04.2023 08:15:07
  • Last modified 13.02.2025 17:16:17

In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code executi...

  • EPSS 3.11%
  • Published 10.04.2023 08:15:07
  • Last modified 13.02.2025 17:16:17

In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote co...

  • EPSS 0.36%
  • Published 10.04.2023 08:15:06
  • Last modified 13.02.2025 17:16:13

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2.  For versions <=1.3.1, we suggest turning...

  • EPSS 2.66%
  • Published 31.01.2023 10:15:10
  • Last modified 27.03.2025 15:15:38

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source an...

  • EPSS 0.11%
  • Published 31.01.2023 10:15:09
  • Last modified 27.03.2025 15:15:37

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Ther...

  • EPSS 1.19%
  • Published 26.10.2022 16:15:11
  • Last modified 07.05.2025 19:16:05

In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and mal...