Skip to content
linkisGHSA-m757-p8rv-4q93

Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged

Medium5.3CVE-2023-50740 · Published Mar 6, 2024 · updated Feb 13, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.linkis:linkis
Maven
< 1.5.01.5.0
Details and references

In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module.  We recommend users upgrade the version of Linkis to version 1.5.0

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-532
Also known as
CVE-2023-50740

More linkis advisories

All
DateAdvisory
Aug 22024Apache Linkis arbitrary file deletion vulnerability
CVE-2024-27182High4.9fixed in 1.6.0
Aug 22024Apache Linkis vulnerable to privilege escalation
CVE-2024-27181High5.3fixed in 1.6.0
Jul 62023Apache Linkis Authentication Bypass vulnerability
CVE-2023-27987Critical9.1fixed in 1.3.2
Jul 62023Apache Linkis Zip Slip issue
CVE-2023-27603Critical9.8fixed in 1.3.2
Jul 62023Apache Linkis Unrestricted File Upload vulnerability
CVE-2023-27602Critical9.8fixed in 1.3.2
Jan 312023Apache Linkis contains Deserialization of Untrusted Data
CVE-2022-44645High8.8fixed in 1.3.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.