Skip to content
linkisGHSA-v352-rg37-5q5m

Apache Linkis vulnerable to privilege escalation

High5.3CVE-2024-27181 · Published Aug 2, 2024 · updated Jun 4, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.linkis:linkis
Maven
< 1.6.01.6.0
Details and references

In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-269
Also known as
CVE-2024-27181

More linkis advisories

All
DateAdvisory
Aug 22024Apache Linkis arbitrary file deletion vulnerability
CVE-2024-27182High4.9fixed in 1.6.0
Mar 62024Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
CVE-2023-50740Medium5.3fixed in 1.5.0
Jul 62023Apache Linkis Authentication Bypass vulnerability
CVE-2023-27987Critical9.1fixed in 1.3.2
Jul 62023Apache Linkis Zip Slip issue
CVE-2023-27603Critical9.8fixed in 1.3.2
Jul 62023Apache Linkis Unrestricted File Upload vulnerability
CVE-2023-27602Critical9.8fixed in 1.3.2
Jan 19Apache Linkis: Arbitrary File Read via Double URL Encoding Bypass
CVE-2025-29847High7.5fixed in 1.8.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.