Arbitrary File Reading Vulnerability in Apache Linkis = 1.4.0
CVE-2023-41916
6.5MEDIUM
What is CVE-2023-41916?
In Apache Linkis version 1.4.0, a vulnerability exists that allows an attacker with an authorized account to exploit the DataSource Manager Module. The flaw arises from inadequate filtering of parameters in the MySQL JDBC configuration. By injecting malicious parameters, an attacker can trigger arbitrary file reading, which could potentially lead to the disclosure of sensitive information. It is crucial that users upgrade to version 1.5.0 to mitigate this risk and protect their systems.
Affected Version(s)
Apache Linkis DataSource 1.4.0 < 1.5.0