linkisGHSA-m757-p8rv-4q93
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Medium5.3CVE-2023-50740 · Published Mar 6, 2024 · updated Feb 13, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.linkis:linkis Maven | < 1.5.0 | 1.5.0 |
Details and references
In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. We recommend users upgrade the version of Linkis to version 1.5.0
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- CVE-2023-50740
More linkis advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 22024 | Apache Linkis arbitrary file deletion vulnerability CVE-2024-27182High4.9fixed in 1.6.0 | High4.9 | 1.6.0 |
| Aug 22024 | Apache Linkis vulnerable to privilege escalation CVE-2024-27181High5.3fixed in 1.6.0 | High5.3 | 1.6.0 |
| Jul 62023 | Apache Linkis Authentication Bypass vulnerability CVE-2023-27987Critical9.1fixed in 1.3.2 | Critical9.1 | 1.3.2 |
| Jul 62023 | Apache Linkis Zip Slip issue CVE-2023-27603Critical9.8fixed in 1.3.2 | Critical9.8 | 1.3.2 |
| Jul 62023 | Apache Linkis Unrestricted File Upload vulnerability CVE-2023-27602Critical9.8fixed in 1.3.2 | Critical9.8 | 1.3.2 |
| Jan 312023 | Apache Linkis contains Deserialization of Untrusted Data CVE-2022-44645High8.8fixed in 1.3.1 | High8.8 | 1.3.1 |