linkisGHSA-rx76-xw35-6rh8
Apache Linkis vulnerable to Exposure of Sensitive Information
Medium6.5CVE-2022-44644 · Published Jan 31, 2023 · updated Nov 8, 2023
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, an authenticated attacker could read arbitrary local file by connecting a rogue mysql server, By adding allowLoadLocalInfile to true in the jdbc parameter. Therefore, the parameters in the jdbc url should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users upgrade the version of Linkis to version 1.3.1
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.linkis:linkis Maven | < 1.3.1 | 1.3.1 |
Details and references
More linkis advisories
All linkis| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 62024 | Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged | Medium5.3 | 1.5.0 |
| Jul 62023 | Apache Linkis Unrestricted File Upload vulnerability | Critical9.8 | 1.3.2 |
| Jul 62023 | Apache Linkis Zip Slip issue | Critical9.8 | 1.3.2 |
| Jul 62023 | Apache Linkis Authentication Bypass vulnerability | Critical9.1 | 1.3.2 |
| Jan 312023 | Apache Linkis contains Deserialization of Untrusted Data | High8.8 | 1.3.1 |
| Oct 262022 | Apache Linkis subject to Remote Code Execution via deserialization | High8.8 | 1.3.0 |