openwall.com
http://www.openwall.com/lists/oss-security/2023/04/10/1 CVE-2023-27602
CRITICAL
Apache Linkis publicsercice module unrestricted upload of file
Record summary
CVE-2023-27602 has a selected CVSS score of 9.8 (critical).
Description
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2. For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties `wds.linkis.workspace.filesystem.owner.check=true` `wds.linkis.workspace.filesystem.path.check=true`
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 22, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Apache LinkisBrowse Apache Software Foundation / Apache LinkisDefault status: unaffected | CVE List | Through 1.3.1 | affected |
linkisBrowse apache / linkisDefault status: unknown | CVE List | Through 1.3.1 | affected |
org.apache.linkis:linkisBrowse Maven / org.apache.linkis:linkis | GitHub Advisory | Before 1.3.2 · Fixed in 1.3.2 | affected |
References
6openwall.com
http://www.openwall.com/lists/oss-security/2023/04/18/4 openwall.com
http://www.openwall.com/lists/oss-security/2023/04/19/3 github.com
https://github.com/apache/linkis lists.apache.orgmailing listVendor advisory
https://lists.apache.org/thread/wt70jfc0yfs6s5g0wg5dr5klnc48nsp1 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-27602