linkisGHSA-h6w8-52mq-4qxc
Apache Linkis contains Deserialization of Untrusted Data
High8.8CVE-2022-44645 · Published Jan 31, 2023 · updated Nov 8, 2023
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and malicious parameters. Therefore, the parameters in the jdbc url should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users to upgrade the version of Linkis to version 1.3.1.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.linkis:linkis Maven | < 1.3.1 | 1.3.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2022-44645
More linkis advisories
All linkis| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 62024 | Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged | Medium5.3 | 1.5.0 |
| Jul 62023 | Apache Linkis Unrestricted File Upload vulnerability | Critical9.8 | 1.3.2 |
| Jul 62023 | Apache Linkis Zip Slip issue | Critical9.8 | 1.3.2 |
| Jul 62023 | Apache Linkis Authentication Bypass vulnerability | Critical9.1 | 1.3.2 |
| Jan 312023 | Apache Linkis vulnerable to Exposure of Sensitive Information | Medium6.5 | 1.3.1 |
| Oct 262022 | Apache Linkis subject to Remote Code Execution via deserialization | High8.8 | 1.3.0 |