Skip to content
linkisGHSA-3f3w-gmqf-4hj3

Apache Linkis subject to Remote Code Execution via deserialization

High8.8CVE-2022-39944 · Published Oct 26, 2022 · updated Nov 8, 2023

In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and malicious parameters. Therefore, the parameters in the jdbc url should be blacklisted. This issue is patched in version 1.3.0, and users are recommended to upgrade.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.linkis:linkis
Maven
< 1.3.01.3.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2022-39944

More linkis advisories

All linkis
Advisory
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Medium5.3Mar 6, 2024
Apache Linkis Unrestricted File Upload vulnerability
Critical9.8Jul 6, 2023
Apache Linkis Zip Slip issue
Critical9.8Jul 6, 2023
Apache Linkis Authentication Bypass vulnerability
Critical9.1Jul 6, 2023
Apache Linkis vulnerable to Exposure of Sensitive Information
Medium6.5Jan 31, 2023
Apache Linkis contains Deserialization of Untrusted Data
High8.8Jan 31, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.