Arbitrary File Reading Vulnerability in Apache Linkis = 1.4.0
CVE-2023-41916
6.5MEDIUM
Summary
In Apache Linkis version 1.4.0, a vulnerability exists that allows an attacker with an authorized account to exploit the DataSource Manager Module. The flaw arises from inadequate filtering of parameters in the MySQL JDBC configuration. By injecting malicious parameters, an attacker can trigger arbitrary file reading, which could potentially lead to the disclosure of sensitive information. It is crucial that users upgrade to version 1.5.0 to mitigate this risk and protect their systems.
Affected Version(s)
Apache Linkis DataSource 1.4.0 < 1.5.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Credit
Pho3n1x
L0ne1y