linkisGHSA-x84r-jrqm-3hj8
Apache Linkis Unrestricted File Upload vulnerability
Critical9.8CVE-2023-27602 · Published Jul 6, 2023 · updated Feb 13, 2025
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2. For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties `wds.linkis.workspace.filesystem.owner.check=true` `wds.linkis.workspace.filesystem.path.check=true`
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.linkis:linkis Maven | < 1.3.2 | 1.3.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-434
- Also known as
- CVE-2023-27602
More linkis advisories
All linkis| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 62024 | Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged | Medium5.3 | 1.5.0 |
| Jul 62023 | Apache Linkis Authentication Bypass vulnerability | Critical9.1 | 1.3.2 |
| Jul 62023 | Apache Linkis Zip Slip issue | Critical9.8 | 1.3.2 |
| Jan 312023 | Apache Linkis contains Deserialization of Untrusted Data | High8.8 | 1.3.1 |
| Jan 312023 | Apache Linkis vulnerable to Exposure of Sensitive Information | Medium6.5 | 1.3.1 |
| Oct 262022 | Apache Linkis subject to Remote Code Execution via deserialization | High8.8 | 1.3.0 |