Skip to content
linkisGHSA-h6w8-52mq-4qxc

Apache Linkis contains Deserialization of Untrusted Data

High8.8CVE-2022-44645 · Published Jan 31, 2023 · updated Nov 8, 2023

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and malicious parameters. Therefore, the parameters in the jdbc url should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users to upgrade the version of Linkis to version 1.3.1.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.linkis:linkis
Maven
< 1.3.11.3.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2022-44645

More linkis advisories

All linkis
Advisory
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Medium5.3Mar 6, 2024
Apache Linkis Unrestricted File Upload vulnerability
Critical9.8Jul 6, 2023
Apache Linkis Zip Slip issue
Critical9.8Jul 6, 2023
Apache Linkis Authentication Bypass vulnerability
Critical9.1Jul 6, 2023
Apache Linkis vulnerable to Exposure of Sensitive Information
Medium6.5Jan 31, 2023
Apache Linkis subject to Remote Code Execution via deserialization
High8.8Oct 26, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.