linkisGHSA-4x5h-xmv4-99wx
Apache Linkis Authentication Bypass vulnerability
Critical9.1CVE-2023-27987 · Published Jul 6, 2023 · updated Oct 18, 2024
In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrade the version of Linkis to version 1.3.2 And modify the default token value. You can refer to Token authorization.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.linkis:linkis Maven | < 1.3.2 | 1.3.2 |
Details and references
More linkis advisories
All linkis| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 62024 | Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged | Medium5.3 | 1.5.0 |
| Jul 62023 | Apache Linkis Zip Slip issue | Critical9.8 | 1.3.2 |
| Jul 62023 | Apache Linkis Unrestricted File Upload vulnerability | Critical9.8 | 1.3.2 |
| Jan 312023 | Apache Linkis contains Deserialization of Untrusted Data | High8.8 | 1.3.1 |
| Jan 312023 | Apache Linkis vulnerable to Exposure of Sensitive Information | Medium6.5 | 1.3.1 |
| Oct 262022 | Apache Linkis subject to Remote Code Execution via deserialization | High8.8 | 1.3.0 |