Skip to content
linkisGHSA-x84r-jrqm-3hj8

Apache Linkis Unrestricted File Upload vulnerability

Critical9.8CVE-2023-27602 · Published Jul 6, 2023 · updated Feb 13, 2025

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2.  For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties `wds.linkis.workspace.filesystem.owner.check=true` `wds.linkis.workspace.filesystem.path.check=true`

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.linkis:linkis
Maven
< 1.3.21.3.2
Details and references

More linkis advisories

All linkis
Advisory
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Medium5.3Mar 6, 2024
Apache Linkis Authentication Bypass vulnerability
Critical9.1Jul 6, 2023
Apache Linkis Zip Slip issue
Critical9.8Jul 6, 2023
Apache Linkis contains Deserialization of Untrusted Data
High8.8Jan 31, 2023
Apache Linkis vulnerable to Exposure of Sensitive Information
Medium6.5Jan 31, 2023
Apache Linkis subject to Remote Code Execution via deserialization
High8.8Oct 26, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.