GHSA-qm2h-m799-86rc
CRITICALCVE-2023-29215In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EngineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. Therefore, the parameters in the Mysql JDBC URL should be blacklisted. Users should upgrade their version of Linkis to version 1.3.2.
- Affected
- < 1.3.2
- Fixed in
- 1.3.2
- Weakness
- CWE-502
- Published
- 2023-04-10
- Source
- github