linkisGHSA-v352-rg37-5q5m
Apache Linkis vulnerable to privilege escalation
High5.3CVE-2024-27181 · Published Aug 2, 2024 · updated Jun 4, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.linkis:linkis Maven | < 1.6.0 | 1.6.0 |
Details and references
In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-269
- Also known as
- CVE-2024-27181
More linkis advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 22024 | Apache Linkis arbitrary file deletion vulnerability CVE-2024-27182High4.9fixed in 1.6.0 | High4.9 | 1.6.0 |
| Mar 62024 | Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged CVE-2023-50740Medium5.3fixed in 1.5.0 | Medium5.3 | 1.5.0 |
| Jul 62023 | Apache Linkis Authentication Bypass vulnerability CVE-2023-27987Critical9.1fixed in 1.3.2 | Critical9.1 | 1.3.2 |
| Jul 62023 | Apache Linkis Zip Slip issue CVE-2023-27603Critical9.8fixed in 1.3.2 | Critical9.8 | 1.3.2 |
| Jul 62023 | Apache Linkis Unrestricted File Upload vulnerability CVE-2023-27602Critical9.8fixed in 1.3.2 | Critical9.8 | 1.3.2 |
| Jan 19 | Apache Linkis: Arbitrary File Read via Double URL Encoding Bypass CVE-2025-29847High7.5fixed in 1.8.0 | High7.5 | 1.8.0 |