Apache Linkis (incubating): The DatasourceManager module has a Local File Read Vulnerability
CVE-2022-44644
6.5MEDIUM
Summary
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Therefore, the parameters in the JDBC URL should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected.
We recommend users upgrade the version of Linkis to version 1.3.1
Affected Version(s)
Apache Linkis (incubating) 0 < 1.3.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Department of Cyber Security Research (Jumbo, Unc1e), Beijing Zhiqian Technology Co., LTD
s3gundo of Hundsun Tech