Apache Linkis (incubating): The DatasourceManager module has a Local File Read Vulnerability
CVE-2022-44644

6.5MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
31 January 2023

Summary

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Therefore, the parameters in the JDBC URL should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected. 

We recommend users upgrade the version of Linkis to version 1.3.1

Affected Version(s)

Apache Linkis (incubating) 0 < 1.3.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Department of Cyber Security Research (Jumbo, Unc1e), Beijing Zhiqian Technology Co., LTD
s3gundo of Hundsun Tech
.