📦 Linkis

by Apache

🔍 What is Linkis?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-27987

CRITICAL CVSS 9.1 Apr 10, 2023

Apache Linkis versions up to 1.3.1 use a default authentication token that is too simple and predictable, allowing attackers to easily guess or obtain it. This vulnerability enables unauthorized acces...

CVE-2023-29216

CRITICAL CVSS 9.8 Apr 10, 2023

This vulnerability in Apache Linkis allows attackers to execute arbitrary code remotely by exploiting a deserialization flaw when configuring MySQL data sources with malicious parameters. All Apache L...

CVE-2023-27602

CRITICAL CVSS 9.8 Apr 10, 2023

This vulnerability in Apache Linkis allows unauthenticated attackers to upload arbitrary files to any location on the server due to insufficient path validation in the PublicService module. This affec...

CVE-2024-39928

HIGH CVSS 7.5 Sep 25, 2024

Apache Linkis versions up to 1.5.0 use a cryptographically weak random string generator (Commons Lang's RandomStringUtils) for Py4j token generation in Spark EngineConn. This vulnerability could allow...

CVE-2024-27181

HIGH CVSS 8.8 Aug 2, 2024

Apache Linkis versions up to 1.5.0 contain a privilege escalation vulnerability where trusted accounts can access token information they shouldn't have permission to view. This allows attackers with t...

CVE-2023-46801

HIGH CVSS 8.8 Jul 15, 2024

This vulnerability allows authenticated attackers to execute arbitrary code on Apache Linkis servers by exploiting Java deserialization when adding MySQL data sources. It affects Apache Linkis version...

CVE-2024-45627

MEDIUM CVSS 5.9 Jan 14, 2025

This vulnerability in Apache Linkis allows authenticated attackers to read arbitrary files from the server by injecting malicious MySQL JDBC parameters. It affects Apache Linkis versions before 1.7.0....

CVE-2023-41916

MEDIUM CVSS 6.5 Jul 15, 2024

Apache Linkis versions up to 1.4.0 have a vulnerability where attackers with authorized accounts can configure malicious MySQL JDBC parameters to trigger arbitrary file reading. This occurs due to ins...