Skip to content
linkisGHSA-rx76-xw35-6rh8

Apache Linkis vulnerable to Exposure of Sensitive Information

Medium6.5CVE-2022-44644 · Published Jan 31, 2023 · updated Nov 8, 2023

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, an authenticated attacker could read arbitrary local file by connecting a rogue mysql server, By adding allowLoadLocalInfile to true in the jdbc parameter. Therefore, the parameters in the jdbc url should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users upgrade the version of Linkis to version 1.3.1

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.linkis:linkis
Maven
< 1.3.11.3.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-200, CWE-312
Also known as
CVE-2022-44644

More linkis advisories

All linkis
Advisory
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Medium5.3Mar 6, 2024
Apache Linkis Unrestricted File Upload vulnerability
Critical9.8Jul 6, 2023
Apache Linkis Zip Slip issue
Critical9.8Jul 6, 2023
Apache Linkis Authentication Bypass vulnerability
Critical9.1Jul 6, 2023
Apache Linkis contains Deserialization of Untrusted Data
High8.8Jan 31, 2023
Apache Linkis subject to Remote Code Execution via deserialization
High8.8Oct 26, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.