Apache Linkis gateway module token authentication bypass
CVE-2023-27987
What is CVE-2023-27987?
In Apache Linkis versions up to and including 1.3.1, the default token generated during Linkis Gateway deployment exhibits insufficient complexity, making it susceptible to unauthorized access. Attackers can exploit this vulnerability by easily obtaining the default token. To enhance security, it is crucial to upgrade to version 1.3.2 and modify the default token to include randomized elements, following the guidelines provided in the Token authorization documentation. This proactive approach will help safeguard your systems against potential attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Linkis 0 <= 1.3.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved