Information Leakage Vulnerability in Apache Linkis Affects Sensitive Configuration Logs
CVE-2025-59355
What is CVE-2025-59355?
A vulnerability exists in Apache Linkis where the decode() function in org.apache.linkis.metadata.util.HiveUtils may fail to correctly perform Base64 decoding. This issue leads to sensitive information such as Hive Metastore keys and plaintext passwords being logged when decoding fails, thus posing a risk of information leakage. The risk is heightened when log files are accessible to users who are not administrators of the hive-site.xml. Users are urged to update to version 1.8.0 or later, which mitigates this issue by providing desensitized logs that do not expose sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Linkis 1.0.0 <= 1.7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved