linkisGHSA-pj5j-w7mw-w797
Apache Linkis Zip Slip issue
Critical9.8CVE-2023-27603 · Published Jul 6, 2023 · updated Oct 22, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.linkis:linkis Maven | < 1.3.2 | 1.3.2 |
Details and references
In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.
More linkis advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 62023 | Apache Linkis Authentication Bypass vulnerability CVE-2023-27987Critical9.1fixed in 1.3.2 | Critical9.1 | 1.3.2 |
| Jul 62023 | Apache Linkis Unrestricted File Upload vulnerability CVE-2023-27602Critical9.8fixed in 1.3.2 | Critical9.8 | 1.3.2 |
| Jan 312023 | Apache Linkis contains Deserialization of Untrusted Data CVE-2022-44645High8.8fixed in 1.3.1 | High8.8 | 1.3.1 |
| Jan 312023 | Apache Linkis vulnerable to Exposure of Sensitive Information CVE-2022-44644Medium6.5fixed in 1.3.1 | Medium6.5 | 1.3.1 |
| Mar 62024 | Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged CVE-2023-50740Medium5.3fixed in 1.5.0 | Medium5.3 | 1.5.0 |
| Oct 262022 | Apache Linkis subject to Remote Code Execution via deserialization CVE-2022-39944High8.8fixed in 1.3.0 | High8.8 | 1.3.0 |