Skip to content
linkisGHSA-pj5j-w7mw-w797

Apache Linkis Zip Slip issue

Critical9.8CVE-2023-27603 · Published Jul 6, 2023 · updated Oct 22, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.linkis:linkis
Maven
< 1.3.21.3.2
Details and references

In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22, CWE-434
Also known as
CVE-2023-27603

More linkis advisories

All
DateAdvisory
Jul 62023Apache Linkis Authentication Bypass vulnerability
CVE-2023-27987Critical9.1fixed in 1.3.2
Jul 62023Apache Linkis Unrestricted File Upload vulnerability
CVE-2023-27602Critical9.8fixed in 1.3.2
Jan 312023Apache Linkis contains Deserialization of Untrusted Data
CVE-2022-44645High8.8fixed in 1.3.1
Jan 312023Apache Linkis vulnerable to Exposure of Sensitive Information
CVE-2022-44644Medium6.5fixed in 1.3.1
Mar 62024Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
CVE-2023-50740Medium5.3fixed in 1.5.0
Oct 262022Apache Linkis subject to Remote Code Execution via deserialization
CVE-2022-39944High8.8fixed in 1.3.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.