CVE-2023-27602

CVSS v3.1 9.8 (Critical)
98% Progress
EPSS 2.69 % (91th)
2.69% Progress
Affected Products 1
Advisories 1

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.

We recommend users upgrade the version of Linkis to version 1.3.2. 

For versions

<=1.3.1, we suggest turning on the file path check switch in linkis.properties

wds.linkis.workspace.filesystem.owner.check=true
wds.linkis.workspace.filesystem.path.check=true

Weaknesses
CWE-434
Unrestricted Upload of File with Dangerous Type
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2023-04-10 08:15:06
(17 months ago)
Updated Date
2023-04-19 12:15:08
(17 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Linkis 1.3.1 and prior versions cpe:2.3:a:apache:linkis <= 1.3.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...