Lucene search

K
githubGitHub Advisory DatabaseGHSA-X84R-JRQM-3HJ8
HistoryJul 06, 2023 - 7:24 p.m.

Apache Linkis Unrestricted File Upload vulnerability

2023-07-0619:24:13
CWE-434
GitHub Advisory Database
github.com
7
apache linkis
unrestricted file upload
vulnerability
version 1.3.1
file path check
linkis.properties
upgrade

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.027

Percentile

90.5%

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.

We recommend users upgrade the version of Linkis to version 1.3.2.

For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties

wds.linkis.workspace.filesystem.owner.check=true
wds.linkis.workspace.filesystem.path.check=true

Affected configurations

Vulners
Node
org.apache.linkislinkisRange<1.3.2
VendorProductVersionCPE
org.apache.linkislinkis*cpe:2.3:a:org.apache.linkis:linkis:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.027

Percentile

90.5%

Related for GHSA-X84R-JRQM-3HJ8