In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2 parameters in the DataSource Manager Module will result in jndi injection. Therefore, the parameters in the DB2 URL should be blacklisted. This attack requires the attacker to obtain an authorized account from Linkis before it can be carried out. Versions of Apache Linkis <=1.5.0 will be affected. We recommend users upgrade the version of Linkis to version 1.6.0.
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/t68yy52lmv7pxgrxnq6rw7rwvk9tb1xj | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/07/13/5 | |
| https://lists.apache.org/thread/t68yy52lmv7pxgrxnq6rw7rwvk9tb1xj | Mailing List Vendor Advisory |
21 Nov 2024, 08:33
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://lists.apache.org/thread/t68yy52lmv7pxgrxnq6rw7rwvk9tb1xj - Mailing List, Vendor Advisory |
16 Jul 2024, 18:06
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| First Time |
Apache linkis
Apache |
|
| References | () https://lists.apache.org/thread/t68yy52lmv7pxgrxnq6rw7rwvk9tb1xj - Mailing List, Vendor Advisory | |
| CPE | cpe:2.3:a:apache:linkis:*:*:*:*:*:*:*:* |
15 Jul 2024, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-07-15 08:15
Updated : 2025-03-27 16:15
NVD link : CVE-2023-49566
Mitre link : CVE-2023-49566
CVE.ORG link : CVE-2023-49566
JSON object : View
Deserialization of Untrusted Data